Information disclosure
- Severity
- High8.6CVSS 3.1, High
- EPSS
- 100%
- Published
- 28 May 2024
- Updated
- 5 Aug 2026
Description
Title, description and vendor guidance are quoted from the source records.
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
Weakness: CWE-200
Known exploited
Added to CISA KEV on 30 May 2024
Federal remediation due date: 20 Jun 2024
Known use in ransomware campaigns
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit prediction
100% probability of exploitation in the next 30 days (percentile 100%).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
What the source states, per branch
Versions matched by Patcharo
Check Point Quantum Security GatewaySource: Check Point (CVE record)
| Branch | Affected | Fixed in |
|---|---|---|
| R81.20 | Listed as affected, no patch-level detail | |
| R81.10 | Listed as affected, no patch-level detail | |
| R81 | Listed as affected, no patch-level detail | |
| R80.40 | Listed as affected, no patch-level detail | |
| R80.20 | Listed as affected, no patch-level detail |
Versions not listed are not assessed (shown as Unknown).
References
- https://support.checkpoint.com/results/sk/sk182336(opens in a new tab)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-24919(opens in a new tab)
- https://www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919/(opens in a new tab)
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Check Point (CVE record)
- Check Point (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 Sept 2026, 23:42 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0
Last verified: 28 Sept 2026, 02:31 UTC