CVE-2024-24919
גבוהה 8.6 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Check Point Quantum Security Gateways Information Disclosure Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
מדדים
- CVSS 3.1
-
8.6 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-200
מוצרים מושפעים
checkpoint: quantum spark firmware; checkpoint: quantum spark; checkpoint: quantum security gateway firmware; checkpoint: quantum security gateway; checkpoint: cloudguard network security
קישורים
- https://support.checkpoint.com/results/sk/sk182336 MitigationPatchVendor Advisory
- https://support.checkpoint.com/results/sk/sk182336 MitigationPatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource
- https://www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-… Third Party Advisory