CVE-2024-24919

HIGH8.6Published on May 28, 2024

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since May 30, 2024
  • US federal agencies must remediate it by Jun 20, 2024 (BOD 22-01)
  • Attacked 2 days before the vulnerability was made public
  • Confirmed by sensors, not only by reports
  • Used in ransomware campaigns

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Source: CISA KEV · Sep 1, 2026 Sep 1, 2026 Aug 31, 2026 Aug 29, 2026 Aug 28, 2026 Aug 27, 2026

CVSS score8.6 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Weakness type (CWE)CWE-200
Vendorscheckpoint

Affected products

VendorsProdottoVersioni
checkpointquantum spark firmwarer80.40
checkpointquantum spark-
checkpointquantum security gateway firmwarer80.40
checkpointquantum security gateway-
checkpointcloudguard network securityr80.40

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database