CVE-2024-24919High· 8.6▾ Abyssal⚠ Exploited in the wildPoC availablePotentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerab…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 47.3 · likelihood 20 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jun 20, 2024
Last analysed / modified upstream
100%
55 GitHub repos · Metasploit ×1 · Nuclei ×1
Added to the CISA catalog on May 30, 2024. Federal remediation due Jun 20, 2024. View catalog ↗
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
quantum_spark_firmware = r80.40quantum_spark_firmware = r81quantum_security_gateway_firmware = r80.40cloudguard_network_security = r80.40cloudguard_network_security = r81cloudguard_network_security = r81.10cloudguard_network_security = r81.20quantum_security_gateway_firmware = r81.20quantum_security_gateway_firmware = r81.10quantum_security_gateway_firmware = r81quantum_spark_firmware = r81.10quantum_spark_firmware = r80.20Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-16232Critical· 9.1An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges
CVE-2026-20805Medium· 5.5Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
CVE-2026-91843Critical· 9.8A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2020-3259High· 7.5A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affecte…