CVE-2024-24919

HIGH8.6Veröffentlicht am 28. Mai 2024

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

Aktiv ausgenutzt

  • Seit dem 30. Mai 2024 im CISA-Katalog ausgenutzter Schwachstellen
  • US-Bundesbehörden müssen sie bis zum 20. Juni 2024 beheben (BOD 22-01)
  • Angegriffen 2 Tage bevor die Schwachstelle öffentlich wurde
  • Durch Sensoren bestätigt, nicht nur durch Meldungen
  • In Ransomware-Kampagnen eingesetzt

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Quelle: CISA KEV · 1. Sept. 2026 31. Aug. 2026 29. Aug. 2026 28. Aug. 2026 27. Aug. 2026 26. Aug. 2026

CVSS-Score8.6 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Schwachstellentyp (CWE)CWE-200
Herstellercheckpoint

Betroffene Produkte

HerstellerProdottoVersioni
checkpointquantum spark firmwarer80.40
checkpointquantum spark-
checkpointquantum security gateway firmwarer80.40
checkpointquantum security gateway-
checkpointcloudguard network securityr80.40

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE-Datenbank