8.6
CVE-2024-24919
- EPSS 94.34%
- Veröffentlicht 28.05.2024 19:15:10
- Zuletzt bearbeitet 30.07.2025 19:25:27
- Quelle cve@checkpoint.com
- Teams Watchlist Login
- Unerledigt Login
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Checkpoint ≫ Quantum Spark Firmware Versionr80.40
Checkpoint ≫ Quantum Spark Firmware Versionr81
Checkpoint ≫ Quantum Security Gateway Firmware Versionr80.40
Checkpoint ≫ Cloudguard Network Security Versionr80.40
Checkpoint ≫ Cloudguard Network Security Versionr81
Checkpoint ≫ Cloudguard Network Security Versionr81.10
Checkpoint ≫ Cloudguard Network Security Versionr81.20
Checkpoint ≫ Quantum Security Gateway Firmware Versionr81.20
Checkpoint ≫ Quantum Security Gateway Firmware Versionr81.10
Checkpoint ≫ Quantum Security Gateway Firmware Versionr81
Checkpoint ≫ Quantum Spark Firmware Versionr81.10
Checkpoint ≫ Quantum Spark Firmware Versionr80.20
30.05.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog
Check Point Quantum Security Gateways Information Disclosure Vulnerability
SchwachstelleCheck Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.
BeschreibungApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Erforderliche MaßnahmenTyp | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 94.34% | 0.999 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
|
cve@checkpoint.com | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.