Rapid7 Vulnerability & Exploit Database

Check Point: Quantum Gateway Information Disclosure: CVE-2024-24919

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Check Point: Quantum Gateway Information Disclosure: CVE-2024-24919

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
05/28/2024
Created
05/31/2024
Added
05/29/2024
Modified
06/03/2024

Description

A vulnerability in Check Point Security Gateways with IPSec VPN, Remote Access VPN and the Mobile Access software blade allows disclosure of information. The vendor advisory does not specify what information may be disclosed, but does recommend rotating passwords and certificates stored on the device. Check Point discovered this vulnerability while investigating attempts to gain unauthorized access to VPN products used by their customers.

Solution(s)

  • checkpoint-cve-2024-24919

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;