HIGH

CVE-2024-24919

Checkpoint Quantum Spark Firmware 2024-05-28 CVSS v3.1
CVSS
8.6
KEV

Description

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

Summary dbcve.org

This is an information disclosure vulnerability in Check Point Security Gateways. When the Remote Access VPN or Mobile Access Software Blades are enabled and the gateway is connected to the internet, an unauthenticated attacker may be able to read certain sensitive information from the affected device.

Mitigation

Apply the Check Point security fix/patch to all affected Security Gateways. If Remote Access VPN or Mobile Access Software Blades are not required for business operations, consider disabling them to reduce the attack surface.

Patch Commit

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

99.98%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE