CVE-2024-24919

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
References
Link Resource
https://support.checkpoint.com/results/sk/sk182336 Mitigation Patch Vendor Advisory
https://support.checkpoint.com/results/sk/sk182336 Mitigation Patch Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:checkpoint:cloudguard_network_security:r80.40:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:cloudguard_network_security:r81.0:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:cloudguard_network_security:r81.10:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:cloudguard_network_security:r81.20:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81.20:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81.10:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81.0:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:checkpoint:quantum_spark_firmware:r81.10:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:checkpoint:quantum_spark_firmware:r80.20:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://support.checkpoint.com/results/sk/sk182336 - Mitigation, Patch, Vendor Advisory () https://support.checkpoint.com/results/sk/sk182336 - Mitigation, Patch, Vendor Advisory

31 May 2024, 16:04

Type Values Removed Values Added
First Time Checkpoint quantum Security Gateway Firmware
Checkpoint quantum Spark Firmware
Checkpoint quantum Security Gateway
Checkpoint cloudguard Network Security
Checkpoint quantum Spark
Checkpoint
References () https://support.checkpoint.com/results/sk/sk182336 - () https://support.checkpoint.com/results/sk/sk182336 - Mitigation, Patch, Vendor Advisory
CPE cpe:2.3:o:checkpoint:quantum_spark_firmware:r80.20:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81.10:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81.20:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81.0:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:cloudguard_network_security:r81.0:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:quantum_spark_firmware:r81.10:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:cloudguard_network_security:r81.10:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark:-:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:cloudguard_network_security:r81.20:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:cloudguard_network_security:r80.40:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

30 May 2024, 13:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 8.6

29 May 2024, 13:02

Type Values Removed Values Added
Summary
  • (es) Potencialmente, permitir que un atacante lea cierta información en Check Point Security Gateways una vez conectado a Internet y habilitado con VPN de acceso remoto o software Blades de acceso móvil. Hay disponible una solución de seguridad que mitiga esta vulnerabilidad.

28 May 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-28 19:15

Updated : 2025-01-27 21:42


NVD link : CVE-2024-24919

Mitre link : CVE-2024-24919

CVE.ORG link : CVE-2024-24919


JSON object : View

Products Affected

checkpoint

  • quantum_security_gateway
  • cloudguard_network_security
  • quantum_spark
  • quantum_security_gateway_firmware
  • quantum_spark_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo