{"id":"CVE-2024-24919","title":"Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades","summary":"Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerab…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-200"],"vendor":"checkpoint","product":"cloudguard_network_security","affected":["quantum_spark_firmware = r80.40","quantum_spark_firmware = r81","quantum_security_gateway_firmware = r80.40","cloudguard_network_security = r80.40","cloudguard_network_security = r81","cloudguard_network_security = r81.10","cloudguard_network_security = r81.20","quantum_security_gateway_firmware = r81.20","quantum_security_gateway_firmware = r81.10","quantum_security_gateway_firmware = r81","quantum_spark_firmware = r81.10","quantum_spark_firmware = r80.20"],"published":"2024-05-28","updated":"2026-08-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-24919","references":[{"url":"https://support.checkpoint.com/results/sk/sk182336","label":"cve@checkpoint.com"},{"url":"https://support.checkpoint.com/results/sk/sk182336","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-24919","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.99978,"epssPercentile":0.9998,"kev":true,"kevDateAdded":"2024-05-30","kevDueDate":"2024-06-20","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-05T11:47:23.328Z","exploits":{"github":55,"githubRepos":["https://github.com/c3rrberu5/CVE-2024-24919","https://github.com/emanueldosreis/CVE-2024-24919","https://github.com/hendprw/CVE-2024-24919"],"metasploit":["auxiliary/gather/checkpoint_gateway_fileread_cve_2024_24919"],"nuclei":["CVE-2024-24919"],"checkedAt":"2026-09-19T16:22:55.900Z"},"exploitAvailable":true,"slug":"CVE-2024-24919","body":"## Overview\n\nPotentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.\n\n## Affected\n\n- `quantum_spark_firmware = r80.40`\n- `quantum_spark_firmware = r81`\n- `quantum_security_gateway_firmware = r80.40`\n- `cloudguard_network_security = r80.40`\n- `cloudguard_network_security = r81`\n- `cloudguard_network_security = r81.10`\n- `cloudguard_network_security = r81.20`\n- `quantum_security_gateway_firmware = r81.20`\n- `quantum_security_gateway_firmware = r81.10`\n- `quantum_security_gateway_firmware = r81`\n- `quantum_spark_firmware = r81.10`\n- `quantum_spark_firmware = r80.20`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":97,"depthScoreParts":{"impact":47.3,"likelihood":20,"exploitation":25,"ransomware":5},"changes":[{"seq":4701,"id":"CVE-2024-24919","ts":1788887200266,"field":"exploit_available","old":"false","new":"true"},{"seq":3584,"id":"CVE-2024-24919","ts":1788886316757,"field":"exploit_available","old":"true","new":"false"},{"seq":2438,"id":"CVE-2024-24919","ts":1788882985498,"field":"exploit_available","old":"false","new":"true"},{"seq":1467,"id":"CVE-2024-24919","ts":1788882398788,"field":"exploit_available","old":"true","new":"false"},{"seq":581,"id":"CVE-2024-24919","ts":1788881835428,"field":"exploit_available","old":"false","new":"true"}]}