CVE-2024-24919
Information disclosure
In short
A vulnerability in Check Point Security Gateways allows attackers to read sensitive information if the gateway is exposed to the internet with remote access VPN or Mobile Access enabled. This can leak confidential data that should be protected.
Technical detail
Information disclosure vulnerability in Check Point Security Gateways (CWE-200) affecting systems with remote Access VPN or Mobile Access Software Blades exposed to the internet. An attacker with network access can retrieve sensitive information without authentication. Requires the vulnerable Blade to be enabled on an internet-facing gateway.
Summary generated and translated by AI from the official description.
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
public PoCs found — 58
githubgithub.com/seed1337/CVE-2024-24919-POC★ 47githubgithub.com/ifconfig-me/CVE-2024-24919-Bulk-Scanner★ 31githubgithub.com/RevoltSecurities/CVE-2024-24919★ 25githubgithub.com/GoatSecurity/CVE-2024-24919★ 20githubgithub.com/un9nplayer/CVE-2024-24919★ 16githubgithub.com/LucasKatashi/CVE-2024-24919★ 12githubgithub.com/0nin0hanz0/CVE-2024-24919-PoC★ 11githubgithub.com/verylazytech/CVE-2024-24919★ 9githubgithub.com/c3rrberu5/CVE-2024-24919★ 7githubgithub.com/geniuszly/CVE-2024-24919★ 6githubgithub.com/emanueldosreis/CVE-2024-24919★ 5githubgithub.com/smackerdodi/CVE-2024-24919-nuclei-templater★ 5githubgithub.com/GuayoyoCyber/CVE-2024-24919★ 4githubgithub.com/zam89/CVE-2024-24919★ 4githubgithub.com/bigb0x/CVE-2024-24919-Sniper★ 3githubgithub.com/Bytenull00/CVE-2024-24919★ 3githubgithub.com/Rug4lo/CVE-2024-24919-Exploit★ 3githubgithub.com/GlobalsecureAcademy/CVE-2024-24919★ 3githubgithub.com/NingXin2002/Check-Point_poc★ 2githubgithub.com/r4p3c4/CVE-2024-24919-Exploit-PoC-Checkpoint-Firewall-VPN★ 2githubgithub.com/Cappricio-Securities/CVE-2024-24919★ 2githubgithub.com/SalehLardhi/CVE-2024-24919★ 1githubgithub.com/starlox0/CVE-2024-24919-POC★ 1githubgithub.com/r4p3c4/CVE-2024-24919-Checkpoint-Firewall-VPN-Check★ 1githubgithub.com/0xans/CVE-2024-24919★ 1githubgithub.com/mr-kasim-mehar/CVE-2024-24919-Exploit★ 1githubgithub.com/satriarizka/CVE-2024-24919★ 1githubgithub.com/birdlex/cve-2024-24919-checker★ 1githubgithub.com/intel365/CVE-2024-24919★ 1githubgithub.com/hashdr1ft/SOC_287★ 1githubgithub.com/funixone/CVE-2024-24919---Exploit-Script★ 1githubgithub.com/nexblade12/CVE-2024-24919★ 1githubgithub.com/Praison001/CVE-2024-24919-Check-Point-Remote-Access-VPN★ 1githubgithub.com/fernandobortotti/CVE-2024-24919★ 1githubgithub.com/0xYumeko/CVE-2024-24919★ 1githubgithub.com/MacUchegit/Detecting-and-Analyzing-CVE-2024-24919-Exploitation★ 0githubgithub.com/hendprw/CVE-2024-24919★ 0githubgithub.com/am-eid/CVE-2024-24919★ 0githubgithub.com/P3wc0/CVE-2024-24919★ 0githubgithub.com/Vulnpire/CVE-2024-24919★ 0githubgithub.com/0xkalawy/CVE-2024-24919★ 0githubgithub.com/nicolvsrlr27/CVE-2024-24919★ 0githubgithub.com/YN1337/CVE-2024-24919★ 0githubgithub.com/J4F9S5D2Q7/CVE-2024-24919-CHECKPOINT★ 0githubgithub.com/Expl0itD0g/CVE-2024-24919---Poc★ 0githubgithub.com/Tim-Hoekstra/CVE-2024-24919★ 0githubgithub.com/nullcult/CVE-2024-24919-Exploit★ 0githubgithub.com/satchhacker/cve-2024-24919★ 0githubgithub.com/H3KEY/CVE-2024-24919★ 0githubgithub.com/Jutrm/cve-2024-24919★ 0githubgithub.com/LuisMateo1/Arbitrary-File-Read-CVE-2024-24919★ 0githubgithub.com/AhmedMansour93/Event-ID-263-Rule-Name-SOC287---Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919-★ 0githubgithub.com/sar-3mar/CVE-2024-24919_POC★ 0githubgithub.com/SpiX-7/CVE-2024-24919-POC★ 0githubgithub.com/ejaboz/cve-2024-24919★ 0githubgithub.com/CyprianAtsyor/CVE-2024-24919-Incident-Report.md★ 0githubgithub.com/CyberBibs/Event-ID-263-Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919-★ 0cve_referencewww.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →