KEVIntel
8.6
CVSS
High

CVE-2024-24919

PUBLISHED

Information disclosure

Exploited in the wild Used in malware PoC available Remote Low complexity No user interaction
Vendor
checkpoint
Product
Check Point Quantum Gateway, Spark Gateway and CloudGuard Network
Published
May 28, 2024
EPSS

Description

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

windows cisa malware ransomware nuclei_scanner nessus_scanner

CVSS scores

CVSS v3.1 8.6 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Exploitation status

Exploited in the wild

Recorded 2024-05-30 00:00:00 UTC · Source

Used in malware

Recorded 2024-05-30 00:00:00 UTC · Source

Proof of concept available

Recorded 2024-05-31 10:18:36 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA May 30, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

geniuszly/CVE-2024-24919

github · Created 2024-09-29 08:20:56 UTC · 6 stars

PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing server responses

protonnegativo/CVE-2024-24919

github · Created 2024-06-10 01:29:19 UTC · 2 stars

Python script to automate the process of finding vulnerable sites for CVE-2024-24919.

verylazytech/CVE-2024-24919

github · Created 2024-06-09 06:54:51 UTC · 9 stars

POC - CVE-2024–24919 - Check Point Security Gateways

GuayoyoCyber/CVE-2024-24919

github · Created 2024-06-03 18:17:45 UTC · 5 stars

Nmap script to check vulnerability CVE-2024-24919

0nin0hanz0/CVE-2024-24919-PoC

github · Created 2024-06-03 13:30:31 UTC · 6 stars

Rug4lo/CVE-2024-24919-Exploit

github · Created 2024-06-03 12:18:35 UTC · 3 stars

CVE-2024-24919 Exploit and PoC - Critical LFI for Remote Access VPN or Mobile Access.

bigb0x/CVE-2024-24919-Sniper

github · Created 2024-06-02 20:16:22 UTC · 2 stars

CVE-2024-24919 Sniper - A powerful tool for scanning Check Point Security Gateway CVE-2024-24919 vulnerability. Supports single & bulk scanning, multithreading, and generates detailed CSV reports. Ideal for penetration testers and security researchers.

r4p3c4/CVE-2024-24919-Exploit-PoC-Checkpoint-Firewall-VPN

github · Created 2024-06-01 12:02:43 UTC · 2 stars

Herramienta de explotación para explotar la vulnerabilidad CVE-2024-24919 en las VPN de Checkpoint Firewall

ifconfig-me/CVE-2024-24919-Bulk-Scanner

github · Created 2024-06-01 10:51:14 UTC · 31 stars

CVE-2024-24919 [Check Point Security Gateway Information Disclosure]

un9nplayer/CVE-2024-24919

github · Created 2024-05-31 18:14:19 UTC · 16 stars

This repository contains a proof-of-concept (PoC) exploit for CVE-2024-24919, a critical vulnerability discovered in Check Point SVN. The vulnerability allows for reading system files. CVE ID: CVE-2024-24919

GlobalsecureAcademy/CVE-2024-24919

github · Created 2024-05-31 17:14:48 UTC · 3 stars

Exploit tool to validate CVE-2024-24919 vulnerability on Checkpoint Firewall VPNs

GoatSecurity/CVE-2024-24919

github · Created 2024-05-31 13:11:40 UTC · 17 stars

CVE-2024-24919 exploit

smackerdodi/CVE-2024-24919-nuclei-templater

github · Created 2024-05-31 12:33:34 UTC · 4 stars

Nuclei template for CVE-2024-24919

seed1337/CVE-2024-24919-POC

github · Created 2024-05-31 11:52:59 UTC · 49 stars

RevoltSecurities/CVE-2024-24919

github · Created 2024-05-31 10:18:36 UTC · 23 stars

An Vulnerability detection and Exploitation tool for CVE-2024-24919

zam89/CVE-2024-24919

github · Created 2024-05-31 07:59:17 UTC · 3 stars

Simple POC Python script that check & leverage Check Point CVE-2024-24919 vulnerability (Wrong Check Point)

Bytenull00/CVE-2024-24919

github · Created 2024-05-30 20:14:19 UTC · 3 stars

Quick and simple script that takes as input a file with multiple URLs to check for the CVE-2024-24919 vulnerability in CHECKPOINT

LucasKatashi/CVE-2024-24919

github · Created 2024-05-30 16:23:18 UTC · 13 stars

CVE-2024-24919 Exploit PoC

emanueldosreis/CVE-2024-24919

github · Created 2024-05-30 14:41:32 UTC · 5 stars

POC exploit for CVE-2024-24919 information leakage

c3rrberu5/CVE-2024-24919

github · Created 2024-05-30 07:55:53 UTC · 6 stars

Nuclei Template to discover CVE-2024-24919. A path traversal vulnerability in CheckPoint SSLVPN.

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nessus

  • Proof of Concept Exploit Available

  • Detected by Nuclei