CVE-2024-24919

HIGH8.6Publicada el 28 de mayo de 2024

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

Explotada activamente

  • En el catálogo CISA de vulnerabilidades explotadas desde el 30 may 2024
  • Las agencias federales de EE. UU. deben corregirla antes del 20 jun 2024 (BOD 22-01)
  • Atacada 2 días antes de que la vulnerabilidad se hiciera pública
  • Confirmada por sensores, no solo por informes
  • Utilizada en campañas de ransomware

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Fuente: CISA KEV · 1 sept 2026 1 sept 2026 31 ago 2026 29 ago 2026 28 ago 2026 27 ago 2026

Puntuación CVSS8.6 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Tipo de debilidad (CWE)CWE-200
Fabricantescheckpoint

Productos afectados

FabricantesProdottoVersioni
checkpointquantum spark firmwarer80.40
checkpointquantum spark-
checkpointquantum security gateway firmwarer80.40
checkpointquantum security gateway-
checkpointcloudguard network securityr80.40

Artículos relacionados

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de datos CVE