sk182336 - Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure
Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure
Please read this important update from Check Point.
Security Alert: High
Product: Cloud Firewall, Maestro HyperScale Firewall, Scalable Chassis, Security Gateways, Spark Firewall
Version: R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20.X (EOS), R80.20SP (EOS), R80.30 (EOS), R80.30SP (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20
OS: Gaia
Last Modified: 2025-09-01
Solution
This article refers to Quantum Security Gateways running Gaia OS and CloudGuard Network Security.
Following our security update on May 27, 2024, Check Point's dedicated task force continues investigating attempts to gain unauthorized access to VPN products used by our customers. On May 28, 2024 we discovered a vulnerability in Security Gateways with IPsec VPN in Remote Access VPN community and the Mobile Access software blade (CVE-2024-24919). Exploiting this vulnerability can result in accessing sensitive information on the Security Gateway.
This, in certain scenarios, can potentially lead the attacker to move laterally and gain domain admin privileges.
If you need any additional assistance, contact Check Point Support or your local Check Point representative.
Table of Contents
- Recommended step - Install Jumbo Hotfix Accumulator to fix CVE-2024-24919
- Security Gateway Hotfix to prevent exploit of CVE-2024-24919
- Important extra measures
- Additional Frequently Asked Questions
- Article Revision History
Note: You are protected from CVE-2024-24919 if your Security Gateway already runs one of these versions:
- R81.20 Jumbo Hotfix Accumulator Recommended Take 65
- R81.10 Jumbo Hotfix Accumulator Recommended Take 150
- R81 Jumbo Hotfix Accumulator Recommended Take 99
Recommended step - Install Jumbo Hotfix Accumulator to fix CVE-2024-24919
The fix is included in these Jumbo Hotfix Accumulators
Note that Check Point Recommended version for all deployments is R82 with its Recommended Jumbo Hotfix Accumulator Take.
| Version | Take # |
| R81.20 Jumbo Hotfix Accumulator | Recommended Take 65 |
| R81.10 Jumbo Hotfix Accumulator | Recommended Take 150 |
| R81 Jumbo Hotfix Accumulator | Recommended Take 99 |
To verify that you are up to date, go to the Gateways and Servers tab in SmartConsole and verify that all your Security Gateways show "Up to date," as shown in the screenshot below. If not, install the Recommended Jumbo Hotfix.
If you wish not to install the Jumbo Hotfix Accumulator, the following hotfix is available:
Security Gateway Hotfix to prevent exploit of CVE-2024-24919
Perform this step on ANY Security Gateway and Cluster that has EITHER of the following setups:
- The IPSec VPN Software Blade is enabled, but ONLY when included in the Remote Access VPN community.
- The Mobile Access Software Blade is enabled.
For online Security Gateways and Cluster Members, the Hotfix is available for you in CPUSE. To obtain the Hotfix:
In a web browser, connect to Gaia Portal on the Security Gateway / each Cluster Member.
Install the hotfix package:
| CPUSE View | Instructions |
| Default | 1. Go to Upgrades (CPUSE) > Status and Actions. \n 2. In the top right corner, click Check For Updates. \n 3. In the Hotfixes section, right-click the hotfix package " Hotfix for CVE-2024-24919" and click Install Update. \n |
| New Experience | 1. Go to Software Updates > Available Updates. \n 2. In the top right corner, click Check for updates. \n 3. In the Hotfix Updates section, in the " Hotfix for CVE-2024-24919" row, click Install. \n |
The process should take 5 to 10 minutes to complete and the confirmation window appears.
- Reboot the Security Gateway / Cluster Member.
Procedure for customers using CCCD - an Advanced VPN feature in R81.10 / R81.20
In R81.10, a new feature was introduced to improve VPN performance: CCCD.
This feature is disabled by default, and is used by a very small number of Security Gateways globally.
Customers who use CCCD must disable this functionality for the Hotfix to be effective.
Follow these steps to check the current CCCD state and disable it:
Log in to the command line (Expert mode) on the Security Gateway / each Cluster Member.
Run the command:
vpn cccd status
The expected output is: vpn: 'cccd' is disabled.
If the output differs, permanently disable the CCCD process by running the vpn cccd disable command.
Note: This change survives a Security Gateway reboot.
Procedure to identify vulnerable Security Gateways
Use this procedure to run the script that scans all the Security Gateways and Cluster Members configured in your Security Management Server or Domain Management Server. The script shows a list of Security Gateways / Clusters that have Remote Access VPN or Mobile Access blade enabled. The recommended action is to install the Security Gateway Hotfix. The updated script checks if the Hotfix is installed.
| Important Note: To run a script from SmartConsole, the permission profile of a Management administrator must have these permissions on the Gateways page in the Scripts section: \n1. Run Repository Script \n2. Manage Repository Scripts |
Procedure:
Download the archive check-for-CVE-2024-24919-v3.zip to your computer.
Extract the check-for-CVE-2024-24919.sh script file from the archive to a local directory.
Connect with SmartConsole to your Security Management Server (on a Multi-Domain Server, connect to any Domain Management Server).
From the left navigation panel, go to Gateways & Servers view.
Click the Security Management Server object (and not a Security Gateway).
From the the top toolbar, click Scripts > Scripts Repository.
The Script Repository window opens.
Add the downloaded script to the repository:
- From the top toolbar, click New.
In the Name field, paste: Check for CVE-2024-24919
Optional: In the Comment field, paste: Check my gateways for CVE-2024-24919 (sk182336)
Click Load from file > select the script file ( check-for-CVE-2024-24919.sh).
Wait for the script content to appear.
Click OK.
Run the script:
- In the Script Repository window, select the newly added script.
From the top toolbar, click Run.
The Run 'Check for CVE-2024-24919' On '
' window opens.
Note for Multi-Domain Management: By default, the script scans all Domain Management Servers (Domains) on the current Multi-Domain Server (MDS), both Active and Standby. In case some Domain Management Servers do not exist on the current Multi-Domain Server, make sure to run the script on additional Multi-Domain Servers as well.
The ability to scan multiple Domains, regardless to which Domain the administrator is currently connected, leverages the strong Run-Script permissions of an administrator that can access all Domains. It is meant to simplify the scanning all Domains on the Multi-Domain Server. To restrict the script to scan only a specific Domain, enter the Domain Name in the Arguments field.
Click Run.
Close the Script Repository window.
Wait a few seconds for the script to complete - see the SmartConsole bottom left corner.
Get the script results:
In the SmartConsole bottom-left corner, click the Task Monitoring pane > in the completed script task Run Repository Script, click Details.
The Run Repository Script window opens.
In the Results section, click the Show results link.
Example result:
> `ALERT: The script identified vulnerable or potentially vulnerable gateways. Review sk182336 and details below for recommended actions. \n > Number of vulnerable Remote Access gateway(s) identified: 1 \n > Recommendation: Install Hotfix to mitigate CVE-2024-24919. \n > - gw8110 \n > Number of gateway(s) that are potentially vulnerable and need to be checked manually for hotfix installation: 1 \n > - cluster8110 \n > Number of gateway(s) that have a Hotfix but require further remediation of disabling cccd: 1 \n > - gw_with_hotfix
Manual Check specifications - On Quantum Maestro, script checks for Hotfix installation only on the main member. Other members should be checked manually. - The script does not currently check for Hotfix installation on the below gateway types, but gives an indication that those gateways should be checked manually: - each Quantum Spark Appliance - Full HA cluster (a cluster of two Standalone gateways) - each VS (no need to check the VSX gateway/cluster)
10. Install the recommended hotfix on the vulnerable Security Gateways and Cluster Members:
- On online Security Gateways / Cluster Members, the hotfix appears in Gaia Portal and Gaia Clish.
- For offline Security Gateways / Cluster Members, refer to the summary table with manual downloads.
The Security Gateway Hotfix is also available for manual download from this table:
| Hotfix on top | Download link |
| Quantum Security Gateway | |
| R81.20 Jumbo Hotfix Accumulator Take 54 | (TAR) |
| R81.20 Jumbo Hotfix Accumulator Take 53 | (TAR) |
| R81.20 Jumbo Hotfix Accumulator Take 41 | (TAR) |
| R81.20 Jumbo Hotfix Accumulator Take 26 | (TAR) |
| R81.10 Jumbo Hotfix Accumulator Take 141 | (TAR) |
| R81.10 Jumbo Hotfix Accumulator Take 139 | (TAR) |
| R81.10 Jumbo Hotfix Accumulator Take 130 | (TAR) |
| R81.10 Jumbo Hotfix Accumulator Take 110 | (TAR) |
| R81 Jumbo Hotfix Accumulator Take 92 | (TAR) |
| R80.40 Jumbo Hotfix Accumulator Take 211 | (TGZ) |
| R80.40 Jumbo Hotfix Accumulator Take 206 | (TGZ) |
| R80.40 Jumbo Hotfix Accumulator Take 198 | (TGZ) |
| R80.40 Jumbo Hotfix Accumulator Take 197 | (TGZ) |
| R80.30 Kernel 2.6 Jumbo Hotfix Accumulator Take 255 | (TGZ) |
| R80.30 Kernel 3.10 Jumbo Hotfix Accumulator Take 255 | (TGZ) |
| R80.20 Jumbo Hotfix Accumulator Take 230 | (TGZ) |
| R80.10 Jumbo Hotfix Accumulator Take 298 | (TGZ) |
| R77.30 Jumbo Hotfix Accumulator Take 351 | (TGZ) |
| R77.30 Jumbo Hotfix Accumulator Take 338 | (TGZ) |
| Quantum Maestro and Quantum Scalable Chassis | |
| R80.30SP Jumbo Hotfix Accumulator Take 97 | (TGZ) |
| R80.20SP Jumbo Hotfix Accumulator Take 336 | (TGZ) |
| Quantum Spark Appliances | |
| See sk182357: Preventative Hotfix for CVE-2024-24919 - Quantum Spark Gateways |
For manual hotfix installation instructions on Quantum Security Gateways, see: sk168597 - How to install a Hotfix.
Automatic interim preventative measure deployed through AutoUpdater utility
Security Gateways that were configured to the Check Point's Auto Update process are gradually receiving an update (as of June 2, 2024), which helps protect them from various attempts to exploit the CVE. This is an interim preventative measure until the Hotfix is fully installed on customers' Security Gateways. It is important to emphasize that installing the Hotfix is the best way to stay protected from this vulnerability.
How to configure Auto Update on your Security Gateways:
Auto Update is enabled by default on all Security Gateways. To verify that it is enabled:
- For versions R81.20 and higher:
- In SmartConsole top-left corner, click the Menu button.
- Click Global properties.
- In the Data Access Control pane, select these checkboxes:
- Automatically download and install Software Blade Contracts, security updates, and other important data (highly recommended)
- Automatically download software updates and new features (highly recommended)
- Click OK
- Install the Access Control policy
- For versions R81.10 and lower:
- In SmartConsole top left-corner, click the Menu button.
- Click Global properties.
- In the Security Management pane, select the " Automatically download and install Blade Contracts, new software, and other important data (highly recommended)" checkbox.
- Click OK
- Install the Access Control policy
For more information, refer to:
- sk175504: How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.20 and higher
- sk111080: How to configure Check Point software to upload data to Check Point / download data from Check Point in versions R81.10 and lower
Note: If Automatic Update is not possible, you can download and install the interim mitigation fix (VPNF) from sk182376. This SK article also contains all details about this Update.
Important extra measures
- Change the password of the LDAP Account Unit
If a Security Gateway / Cluster is configured to use an LDAP Account Unit, we recommend changing the password of the LDAP account.
Instructions:
- Change Security Gateway's account in the Active Directory. To do so, refer to this Microsoft article.
- In SmartConsole, open the Object Explorer (press the CTRL+E keys) > Users/Identities > LDAP Account Units
- Right-click the LDAP Account Unit and click Edit.
- Change the password and click OK.
Reset password of local accounts connecting to Remote Access VPN with password-only authentication
In SmartConsole, open the Object Explorer (press the CTRL+E keys) > VPN Communities > Remote Access.
In Participant User Group pane, select the relevant User group.
In the User Group properties, edit the relevant User.
In the User properties window, go to the Authentication page and for Check Point Password click Set new password.
Click OK.
Repeat this procedure for EVERY User with the 'Check Point Password' authentication in ALL User Groups in ALL Remote Access VPN Communities.
Prevent Local Accounts from connecting to VPN with Password-Only Authentication
We recommend not to use local accounts that authenticate the Remote Access VPN users with password-only authentication. This section provides mitigation steps to discover and prevent such accounts from logging into the VPN.
Procedure:
Download the archive check-for-local-users-with-password-only-authentication-v5.zip to your computer.
Extract the check-for-local-users-with-password-only-authentication.sh script file from the archive to a local directory.
Connect with SmartConsole to your Security Management Server (on a Multi-Domain Server, connect to any Domain Management Server).
From the left navigation panel, go to Gateways & Servers view.
Click the Security Management Server object.
From the the top toolbar, click Scripts > Scripts Repository.
The Script Repository window opens.
Add the downloaded script to the repository:
- From the top toolbar, click New.
In the Name field, paste: Check for local users with password-only authentication
Optional: In the Comment field, paste: sk182336
Click Load from file > select the script file check-for-local-users-with-password-only-authentication.sh.
Wait for the script content to appear.
Click OK.
Run the script:
- In the Script Repository window, select the newly added script.
From the top toolbar, click Run.
The Run 'Check for local users with password-only authentication' On '
' window opens.Click Run.
Close the Script Repository window.
Wait a few seconds for the script to complete - see the SmartConsole bottom left corner.
Get the script result:
Analyze the script result.
Install the Hotfix to block Local Accounts with Password-Only Authentication
Additional Frequently Asked Questions
- What are the suspect IP addresses used by threat actors to exploit the vulnerability?
| 5.188.218.0/23 |
| 23.227.196.88 |
| 23.227.203.36 |
| 31.134.0.0/20 |
| 37.9.40.0/21 |
| 37.19.205.180 |
| 38.180.54.104 |
| 38.180.54.168 |
| 45.135.1.0/24 |
| 45.135.2.0/23 |
| 45.155.166.0/23 |
| 46.59.10.72 |
| 46.183.221.194 |
| 46.183.221.197 |
| 61.92.2.219 |
| 64.176.196.84 |
| 68.183.56.130 |
| 82.180.133.120 |
| 85.239.42.0/23 |
| 87.206.110.89 |
| 88.218.44.0/24 |
| 91.132.198.0/24 |
| 91.218.122.0/23 |
| 91.245.236.0/24 |
| 103.61.139.226 |
| 104.207.149.95 |
| 109.134.69.241 |
| 112.163.100.151 |
| 132.147.86.201 |
| 146.70.205.62 |
| 146.70.205.188 |
| 146.185.207.0/24 |
| 149.88.22.67 |
| 154.47.23.111 |
| 156.146.56.136 |
| 158.62.16.45 |
| 162.158.162.254 |
| 167.61.244.201 |
| 167.99.112.236 |
| 178.236.234.123 |
| 183.96.10.14 |
| 185.213.20.20 |
| 185.217.0.242 |
| 192.71.26.106 |
| 193.233.128.0/22 |
| 193.233.216.0/21 |
| 195.14.123.132 |
| 198.44.211.76 |
| 203.160.68.12 |
| 217.145.225.0/24 |
| 221.154.174.74 |
- When were exploitation attempts for this vulnerability first seen?
Our retrospective telemetry analysis shows exploitation attempts starting on 30 April 2024. Further investigation (as of 31 May 2024) revealed that the first exploitation attempts started on 07 April 2024. We are actively investigating further.
- What is the current CVSS score of this vulnerability?
As of 30 May 2024, the CVSS score is 8.6 (High), with the vector string - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
| Parameter | Value | Explanation |
| Attack Vector (AV) | Network | This vulnerability is exploited only through the Network. |
| Attack Complexity (AC) | Low | An attacker can expect repeatable success when attacking the vulnerable component. There are no special conditions or circumstances required for exploit success, assuming the component (VPN) is enabled on the Security Gateway. |
| Privilege Required (PR) | None | The attacker is unauthorized. |
| User Interaction (UI) | None | The vulnerability can be exploited without any user interaction. |
| Scope (S) | Changed | An exploited vulnerability can affect Security Gateway components besides the VPN. |
| Confidentiality (C) | High | All resources within the Security Gateway are potentially accessible to the attacker and are therefore considered compromised. |
| Integrity (I) | None | There is no loss of Security Gateway integrity. |
| Availability (A) | None | There is no impact on the Security Gateway availability. |
- What is the recommendation for a Gateway running an End-of-Support version (R80.30 and lower)?
If you run a version that is already End-of-Support, we recommend one of these options:
- Upgrade to a supported version and install the provided Hotfix.
- Disable the Remote Access and Mobile Access functionalities.
- Is there an IPS Signature that can prevent attempts to exploit CVE-2024-24919?
Yes. The IPS Signature "Check Point VPN Information Disclosure (CVE-2024-24919)" detects and blocks attempts to exploit this CVE.
- If I suspect unauthorized access attempts, what should I do?
To investigate for suspicious activity, we recommend taking these steps:
- I have installed the hotfix "Hardening Remote Access for VPN users". Are the Security Gateways still vulnerable to CVE-2024-24919?
As an initial step, deploy the hotfix for CVE-2024-24919 to address the vulnerability. Implement the additional protection measures if you have Remote Access VPN users who authenticate to the Security Gateway using only a password (see "Important extra measures").
Article Revision History
| Date | Description |
| 15 May 2025 | Updated Important extra measures: - Added the procedure "Renew the VPN default certificate / Multi-Portal certificate on the Security Gateway" - Added the procedure "Renew the 3rd-party certificates for Multi-Portal of each applicable Software Blade on the Security Gateway" |
| 25 June 2024 | Updated Important extra measures: 1. Change the password for Gaia OS scheduled snapshots 2. Change the password for Gaia OS scheduled backups 3. Change the SNMP authentication settings 4. On a Standalone server, change the destination certificates for Log Exporter 5. Change the certificates for Identity Broker on the PDP Gateway |
| 16 Jun 2024 | - R81 Jumbo Hotfix Accumulator Take 99 was declared as Recommended |
| 13 June 2024 | Updated Important extra measures: 1. Change the shared secret in the RADIUS Server settings 2. Change the shared secret in the TACACS+ Server settings |
| 10 June 2024 | 1. Added Hotfix for R77.30 Jumbo Hotfix Accumulator Take 338 2. R81.20 Jumbo Hotfix Accumulator Take 65 and R81.10 Jumbo Hotfix Accumulator Take 150 were declared as Recommended |
| 06 June 2024 | - Added "Update Azure HA Credentials" to the "Important extra measures" section |
| 05 June 2024 | 1. Added R81 Jumbo Hotfix Accumulator Take 99 2. Updated the Procedure to identify vulnerable Security Gateways > Get the script results > Manual Check specifications section 3. Added Hotfix for R77.30 Jumbo Hotfix Accumulator Take 351 4. Added a note and link to sk182376 - Interim preventative measure (VPNF) for CVE-2024-24919 |
| 04 June 2024 | - Updated the "Procedure to identify vulnerable Security Gateways" section |
| 03 June 2024 | 1. Added instruction "How to configure Auto Update on your Security Gateways" 2. Added R81.20 Jumbo Hotfix Accumulator Take 65 |
| 02 June 2024 | 1. Added the "Automatic interim preventative measure deployed through AutoUpdater utility section 2. Added the "Install Jumbo Hotfix Accumulator to fix CVE-2024-24919" section and R81.10 Jumbo Hotfix Accumulator Take 150 |
| 01 June 2024 | 1. Added caution for customers using CCCD in R81.10 / R81.20 2. Added the "Article Revision History" section |