S4E just found a low php technology & version detection scanner
high·Product Based Web Vulnerabilities·Updated Jun 10, 2024

CVE-2024-24919 Scanner

CVE-2024-24919 scanner - Information Disclosure vulnerability in Check Point Quantum Gateway

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
1
Times Used
by S4E users
1
Assets Scanned
domains & IPs
1
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-24919
8.6
CVSShigh
Exploitable remotely over the internet · no authentication required.

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Check Point Quantum Gateway, Spark Gateway and CloudGuard Networkby checkpoint
Check Point Quantum Gateway and CloudGuard Network versions R81.20, R81.10, R81, R80.40 and Check Point Spark versions R81.10, R80.20.
quantum_security_gateway_firmwareby checkpoint
r80.40
quantum_security_gateway_firmwareby checkpoint
r80.40
quantum_security_gateway_firmwareby checkpoint
r80.40
Updated Aug 22, 2026View on NVD →
Detail

Check Point Quantum Gateway is a security solution used by organizations to protect their network infrastructure. It is commonly deployed by IT departments to ensure secure communication through features like IPSec VPN, remote access VPN, and mobile access software blades. This product is widely utilized in enterprise environments to safeguard against unauthorized access and data breaches. By providing robust network security, it helps maintain the integrity and confidentiality of sensitive information. Check Point Quantum Gateway is essential for organizations seeking comprehensive network security solutions.

The Information Disclosure vulnerability in Check Point Quantum Gateway, identified as CVE-2024-24919, allows attackers to access sensitive information. This issue arises when the gateway is configured with IPSec VPN, remote access VPN, or mobile access software blade. An attacker can exploit this vulnerability to obtain critical data such as system files. This can lead to potential security breaches and unauthorized data access.

CVE-2024-24919 affects Check Point Quantum Gateways that are set up with certain VPN configurations. The vulnerability is triggered by sending a crafted HTTP request to the gateway's endpoint, specifically targeting the "/clients/MyCRL" path. The malicious request includes a payload that attempts to traverse directories and access sensitive files like "/etc/shadow". If successful, the server responds with critical information from these files. The presence of this flaw can be verified if the response body contains patterns indicating access to user credential files, such as "root:." and "nobody:.".

Exploitation of this vulnerability can lead to severe security implications. An attacker gaining access to the "/etc/shadow" file can compromise system credentials, potentially leading to unauthorized access and privilege escalation. This can further enable the attacker to manipulate or steal sensitive data, disrupt services, and cause significant damage to the organization's network security. Such breaches can result in data loss, reputational damage, and financial loss.

Join S4E today to leverage our advanced cyber threat exposure management platform. By using our service, you can ensure your digital assets are continuously monitored for vulnerabilities like CVE-2024-24919. Our platform provides detailed reports and actionable insights, helping you maintain robust security measures. Protect your organization from potential breaches and keep your network secure with our comprehensive scanning and alerting capabilities. Become a member now to stay ahead of cyber threats and safeguard your sensitive information.

References:

Solution Advice
  • Update Check Point Quantum Gateway to the latest version that addresses this vulnerability.
  • Implement strict access controls to limit exposure of sensitive endpoints.
  • Regularly monitor and audit network configurations for potential vulnerabilities.
  • Apply security patches and updates promptly to mitigate risks.
  • Configure logging and alerting mechanisms to detect and respond to suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.