PT-2024-3801 · Check Point · Check Point Security Gateway+5

CVE-2024-24919

·

Published

2024-05-26

·

Updated

2026-09-01

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CloudGuard Network (affected versions not specified) Quantum Maestro (affected versions not specified) Quantum Scalable Chassis (affected versions not specified) Quantum Security Gateways (affected versions not specified) Quantum Spark Appliances (affected versions not specified)
Description An information disclosure issue exists in Check Point Security Gateways configured with IPSec VPN or Mobile Access software blades. An unauthenticated remote attacker can read the content of arbitrary files on the affected device, such as the /etc/shadow file, which contains password hashes for local accounts, including those used to connect to Active Directory. This allows attackers to crack hashes and obtain passwords to gain unauthorized access and move laterally within the network. Real-world exploitation has been detected since April 2024, with attackers extracting ntds.dit files to steal Active Directory data. Approximately 45,000 hosts were identified as potentially vulnerable via Fofa and 20,000 via Shodan. The exploitation is achieved through a single POST request.
Recommendations Update CloudGuard Network to the fixed version provided by the vendor. Update Quantum Maestro to the fixed version provided by the vendor. Update Quantum Scalable Chassis to the fixed version provided by the vendor. Update Quantum Security Gateways to the fixed version provided by the vendor. Update Quantum Spark Appliances to the fixed version provided by the vendor. Remove all local users on the affected security gateways. Change passwords and accounts used for LDAP connections from the gateway to Active Directory. Update Check Point IPS signatures to detect exploitation attempts. Perform a log review to identify signs of compromise.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04175
CVE-2024-24919

Affected Products

Check Point Cloudguard Network
Check Point Gaia
Check Point Quantum Maestro
Check Point Quantum Scalable Chassis
Check Point Quantum Spark Appliances
Check Point Security Gateway