CVE-2024-24919: 
Checkpoint CloudGuard Network Security Analyse et atténuation des vulnérabilités

Aperçu

CVE-2024-24919 is a high-severity information disclosure vulnerability affecting Check Point Security Gateway devices configured with either the "IPSec VPN" or "Mobile Access" software blade. The vulnerability was first discovered with exploitation attempts beginning on April 7, 2024, and was officially disclosed by Check Point on May 28, 2024. The affected products include CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances (Rapid7 Blog).

Détails techniques

The vulnerability is a path traversal issue that allows an unauthenticated remote attacker to read the contents of arbitrary files located on the affected appliance. The vulnerability has been assigned a CVSS v3.1 base score of 8.6 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N. The exploitation involves sending a specially crafted POST request to the /clients/MyCRL endpoint, which can be used to traverse the filesystem and read sensitive files (GreyNoise Blog).

Impact

The vulnerability allows attackers to access sensitive information on the Security Gateway, including password hashes from the /etc/shadow file and other sensitive system files. In certain scenarios, this access can potentially lead to lateral movement and domain admin privileges. Attackers can potentially crack the password hashes for local accounts, and if the Security Gateway allows password-only authentication, they may use the cracked passwords to authenticate (Rapid7 Blog).

Exploitabilité

The vulnerability has been actively exploited in the wild since April 7, 2024. Security firm mnemonic has observed threat actors leveraging the vulnerability to enumerate and extract password hashes for all local accounts, including accounts used to connect to Active Directory. Adversaries have been observed moving laterally and extracting the "ntds.dit" file from compromised customers' Active Directory servers within hours of initial attacks. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog (Rapid7 Blog).

Atténuation et solutions de contournement

Check Point has released hotfixes for affected products. Organizations should immediately apply the vendor-provided hotfixes and manually confirm that the CCCD feature is disabled on every patched Check Point device. The command 'vpn cccd status' should be executed in "Expert Mode" on appliances to confirm CCCD is disabled. Additionally, Check Point recommends checking for local account usage, disabling unused local accounts, and implementing certificate-based authentication rather than password-only authentication (Rapid7 Blog).

Réactions de la communauté

The security community has responded rapidly to this vulnerability, with multiple security firms publishing detailed analyses and proof-of-concept demonstrations. On May 30, 2024, watchTowr labs published a detailed technical analysis including a working proof of concept. Censys reported that approximately 14,000 devices are running vulnerable versions of the software, though the exact number of exposed management ports is unclear (GreyNoise Blog).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Checkpoint CloudGuard Network Security Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-85102CRITICAL9.8
  • Checkpoint CloudGuard Network Security logoCheckpoint CloudGuard Network Security
  • cpe:2.3:a:checkpoint:cloudguard_network_security
OuiOuiSep 22, 2026
CVE-2024-24919HIGH8.6
  • Checkpoint CloudGuard Network Security logoCheckpoint CloudGuard Network Security
  • cpe:2.3:a:checkpoint:cloudguard_network_security
OuiOuiMay 28, 2024

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités