CVE-2024-24919: Check Point Quantum Security Gateways Information Disclosure Vulnerability

High severity, CVSS 8.6. Actively exploited: in CISA KEV since 2024-05-30. EPSS: 100% chance of exploitation in the next 30 days.

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

Affected products

  • Check Point Cloudguard Network Security: version r80.40 only; version r81 only; version r81.10 only; version r81.20 only
  • Check Point Quantum Security Gateway Firmware: version r80.40 only; version r81.20 only; version r81.10 only; version r81 only
  • Check Point Quantum Spark Firmware: version r80.40 only; version r81 only; version r81.10 only; version r80.20 only

Published 2024-05-28. Last modified 2026-08-05.