CVE-2024-24919: 
Checkpoint CloudGuard Network Security 脆弱性の分析と軽減

概要

CVE-2024-24919 is a high-severity information disclosure vulnerability affecting Check Point Security Gateway devices configured with either the "IPSec VPN" or "Mobile Access" software blade. The vulnerability was first discovered with exploitation attempts beginning on April 7, 2024, and was officially disclosed by Check Point on May 28, 2024. The affected products include CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances (Rapid7 Blog).

技術的な詳細

The vulnerability is a path traversal issue that allows an unauthenticated remote attacker to read the contents of arbitrary files located on the affected appliance. The vulnerability has been assigned a CVSS v3.1 base score of 8.6 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N. The exploitation involves sending a specially crafted POST request to the /clients/MyCRL endpoint, which can be used to traverse the filesystem and read sensitive files (GreyNoise Blog).

影響

The vulnerability allows attackers to access sensitive information on the Security Gateway, including password hashes from the /etc/shadow file and other sensitive system files. In certain scenarios, this access can potentially lead to lateral movement and domain admin privileges. Attackers can potentially crack the password hashes for local accounts, and if the Security Gateway allows password-only authentication, they may use the cracked passwords to authenticate (Rapid7 Blog).

エクスプロイト可能性

The vulnerability has been actively exploited in the wild since April 7, 2024. Security firm mnemonic has observed threat actors leveraging the vulnerability to enumerate and extract password hashes for all local accounts, including accounts used to connect to Active Directory. Adversaries have been observed moving laterally and extracting the "ntds.dit" file from compromised customers' Active Directory servers within hours of initial attacks. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog (Rapid7 Blog).

軽減策と回避策

Check Point has released hotfixes for affected products. Organizations should immediately apply the vendor-provided hotfixes and manually confirm that the CCCD feature is disabled on every patched Check Point device. The command 'vpn cccd status' should be executed in "Expert Mode" on appliances to confirm CCCD is disabled. Additionally, Check Point recommends checking for local account usage, disabling unused local accounts, and implementing certificate-based authentication rather than password-only authentication (Rapid7 Blog).

コミュニティの反応

The security community has responded rapidly to this vulnerability, with multiple security firms publishing detailed analyses and proof-of-concept demonstrations. On May 30, 2024, watchTowr labs published a detailed technical analysis including a working proof of concept. Censys reported that approximately 14,000 devices are running vulnerable versions of the software, though the exact number of exposed management ports is unclear (GreyNoise Blog).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 Checkpoint CloudGuard Network Security 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-85102CRITICAL9.8
  • Checkpoint CloudGuard Network Security logoCheckpoint CloudGuard Network Security
  • cpe:2.3:a:checkpoint:cloudguard_network_security
はいはいSep 22, 2026
CVE-2024-24919HIGH8.6
  • Checkpoint CloudGuard Network Security logoCheckpoint CloudGuard Network Security
  • cpe:2.3:a:checkpoint:cloudguard_network_security
はいはいMay 28, 2024

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者