8.6
CVE-2024-24919
- EPSS 94.34%
- Published 28.05.2024 19:15:10
- Last modified 30.07.2025 19:25:27
- Source cve@checkpoint.com
- Teams watchlist Login
- Open Login
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
Data is provided by the National Vulnerability Database (NVD)
Checkpoint ≫ Quantum Spark Firmware Versionr80.40
Checkpoint ≫ Quantum Spark Firmware Versionr81
Checkpoint ≫ Quantum Security Gateway Firmware Versionr80.40
Checkpoint ≫ Cloudguard Network Security Versionr80.40
Checkpoint ≫ Cloudguard Network Security Versionr81
Checkpoint ≫ Cloudguard Network Security Versionr81.10
Checkpoint ≫ Cloudguard Network Security Versionr81.20
Checkpoint ≫ Quantum Security Gateway Firmware Versionr81.20
Checkpoint ≫ Quantum Security Gateway Firmware Versionr81.10
Checkpoint ≫ Quantum Security Gateway Firmware Versionr81
Checkpoint ≫ Quantum Spark Firmware Versionr81.10
Checkpoint ≫ Quantum Spark Firmware Versionr80.20
30.05.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog
Check Point Quantum Security Gateways Information Disclosure Vulnerability
VulnerabilityCheck Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.
DescriptionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 94.34% | 0.999 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
|
cve@checkpoint.com | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.