sk182336 - Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure

Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure

Please read this important update from Check Point.

Security Alert: High

Product: Cloud Firewall, Maestro HyperScale Firewall, Scalable Chassis, Security Gateways, Spark Firewall
Version: R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20.X (EOS), R80.20SP (EOS), R80.30 (EOS), R80.30SP (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20
OS: Gaia
Last Modified: 2025-09-01

Solution

This article refers to Quantum Security Gateways running Gaia OS and CloudGuard Network Security.

Following our security update on May 27, 2024, Check Point's dedicated task force continues investigating attempts to gain unauthorized access to VPN products used by our customers. On May 28, 2024 we discovered a vulnerability in Security Gateways with IPsec VPN in Remote Access VPN community and the Mobile Access software blade (CVE-2024-24919). Exploiting this vulnerability can result in accessing sensitive information on the Security Gateway.

This, in certain scenarios, can potentially lead the attacker to move laterally and gain domain admin privileges.

If you need any additional assistance, contact Check Point Support or your local Check Point representative.

Table of Contents

Note: You are protected from CVE-2024-24919 if your Security Gateway already runs one of these versions:

Recommended step - Install Jumbo Hotfix Accumulator to fix CVE-2024-24919

The fix is included in these Jumbo Hotfix Accumulators

Note that Check Point Recommended version for all deployments is R82 with its Recommended Jumbo Hotfix Accumulator Take.

Version Take #
R81.20 Jumbo Hotfix Accumulator Recommended Take 65
R81.10 Jumbo Hotfix Accumulator Recommended Take 150
R81 Jumbo Hotfix Accumulator Recommended Take 99

To verify that you are up to date, go to the Gateways and Servers tab in SmartConsole and verify that all your Security Gateways show "Up to date," as shown in the screenshot below. If not, install the Recommended Jumbo Hotfix.

If you wish not to install the Jumbo Hotfix Accumulator, the following hotfix is available:

Security Gateway Hotfix to prevent exploit of CVE-2024-24919

Perform this step on ANY Security Gateway and Cluster that has EITHER of the following setups:

For online Security Gateways and Cluster Members, the Hotfix is available for you in CPUSE. To obtain the Hotfix:

  1. In a web browser, connect to Gaia Portal on the Security Gateway / each Cluster Member.

  2. Install the hotfix package:

CPUSE View Instructions
Default 1. Go to Upgrades (CPUSE) > Status and Actions. \n 2. In the top right corner, click Check For Updates. \n 3. In the Hotfixes section, right-click the hotfix package " Hotfix for CVE-2024-24919" and click Install Update. \n
New Experience 1. Go to Software Updates > Available Updates. \n 2. In the top right corner, click Check for updates. \n 3. In the Hotfix Updates section, in the " Hotfix for CVE-2024-24919" row, click Install. \n

The process should take 5 to 10 minutes to complete and the confirmation window appears.

  1. Reboot the Security Gateway / Cluster Member.

Procedure for customers using CCCD - an Advanced VPN feature in R81.10 / R81.20

In R81.10, a new feature was introduced to improve VPN performance: CCCD.

This feature is disabled by default, and is used by a very small number of Security Gateways globally.

Customers who use CCCD must disable this functionality for the Hotfix to be effective.

Follow these steps to check the current CCCD state and disable it:

  1. Log in to the command line (Expert mode) on the Security Gateway / each Cluster Member.

  2. Run the command: vpn cccd status

The expected output is: vpn: 'cccd' is disabled.

If the output differs, permanently disable the CCCD process by running the vpn cccd disable command.

Note: This change survives a Security Gateway reboot.

Procedure to identify vulnerable Security Gateways

Use this procedure to run the script that scans all the Security Gateways and Cluster Members configured in your Security Management Server or Domain Management Server. The script shows a list of Security Gateways / Clusters that have Remote Access VPN or Mobile Access blade enabled. The recommended action is to install the Security Gateway Hotfix. The updated script checks if the Hotfix is installed.

Important Note: To run a script from SmartConsole, the permission profile of a Management administrator must have these permissions on the Gateways page in the Scripts section: \n1. Run Repository Script \n2. Manage Repository Scripts

Procedure:

  1. Download the archive check-for-CVE-2024-24919-v3.zip to your computer.

  2. Extract the check-for-CVE-2024-24919.sh script file from the archive to a local directory.

  3. Connect with SmartConsole to your Security Management Server (on a Multi-Domain Server, connect to any Domain Management Server).

  4. From the left navigation panel, go to Gateways & Servers view.

  5. Click the Security Management Server object (and not a Security Gateway).

  6. From the the top toolbar, click Scripts > Scripts Repository.

The Script Repository window opens.

  1. Add the downloaded script to the repository:

    1. From the top toolbar, click New.
  2. In the Name field, paste: Check for CVE-2024-24919

  3. Optional: In the Comment field, paste: Check my gateways for CVE-2024-24919 (sk182336)

  4. Click Load from file > select the script file ( check-for-CVE-2024-24919.sh).

  5. Wait for the script content to appear.

  6. Click OK.

  7. Run the script:

    1. In the Script Repository window, select the newly added script.
  8. From the top toolbar, click Run.

  9. The Run 'Check for CVE-2024-24919' On '' window opens.

Note for Multi-Domain Management: By default, the script scans all Domain Management Servers (Domains) on the current Multi-Domain Server (MDS), both Active and Standby. In case some Domain Management Servers do not exist on the current Multi-Domain Server, make sure to run the script on additional Multi-Domain Servers as well.

The ability to scan multiple Domains, regardless to which Domain the administrator is currently connected, leverages the strong Run-Script permissions of an administrator that can access all Domains. It is meant to simplify the scanning all Domains on the Multi-Domain Server. To restrict the script to scan only a specific Domain, enter the Domain Name in the Arguments field.

  1. Click Run.

  2. Close the Script Repository window.

  3. Wait a few seconds for the script to complete - see the SmartConsole bottom left corner.

  4. Get the script results:

  5. In the SmartConsole bottom-left corner, click the Task Monitoring pane > in the completed script task Run Repository Script, click Details.

  6. The Run Repository Script window opens.

  7. In the Results section, click the Show results link.

Example result:

> `ALERT: The script identified vulnerable or potentially vulnerable gateways. Review sk182336 and details below for recommended actions.  \n    >   Number of vulnerable Remote Access gateway(s) identified: 1  \n    >     Recommendation: Install Hotfix to mitigate CVE-2024-24919.  \n    >     - gw8110  \n    > Number of gateway(s) that are potentially vulnerable and need to be checked manually for hotfix installation: 1  \n    > - cluster8110  \n    > Number of gateway(s) that have a Hotfix but require further remediation of disabling cccd: 1  \n    > - gw_with_hotfix

Manual Check specifications - On Quantum Maestro, script checks for Hotfix installation only on the main member. Other members should be checked manually. - The script does not currently check for Hotfix installation on the below gateway types, but gives an indication that those gateways should be checked manually: - each Quantum Spark Appliance - Full HA cluster (a cluster of two Standalone gateways) - each VS (no need to check the VSX gateway/cluster)
10. Install the recommended hotfix on the vulnerable Security Gateways and Cluster Members: - On online Security Gateways / Cluster Members, the hotfix appears in Gaia Portal and Gaia Clish.

The Security Gateway Hotfix is also available for manual download from this table:

Hotfix on top Download link
Quantum Security Gateway
R81.20 Jumbo Hotfix Accumulator Take 54 (TAR)
R81.20 Jumbo Hotfix Accumulator Take 53 (TAR)
R81.20 Jumbo Hotfix Accumulator Take 41 (TAR)
R81.20 Jumbo Hotfix Accumulator Take 26 (TAR)
R81.10 Jumbo Hotfix Accumulator Take 141 (TAR)
R81.10 Jumbo Hotfix Accumulator Take 139 (TAR)
R81.10 Jumbo Hotfix Accumulator Take 130 (TAR)
R81.10 Jumbo Hotfix Accumulator Take 110 (TAR)
R81 Jumbo Hotfix Accumulator Take 92 (TAR)
R80.40 Jumbo Hotfix Accumulator Take 211 (TGZ)
R80.40 Jumbo Hotfix Accumulator Take 206 (TGZ)
R80.40 Jumbo Hotfix Accumulator Take 198 (TGZ)
R80.40 Jumbo Hotfix Accumulator Take 197 (TGZ)
R80.30 Kernel 2.6 Jumbo Hotfix Accumulator Take 255 (TGZ)
R80.30 Kernel 3.10 Jumbo Hotfix Accumulator Take 255 (TGZ)
R80.20 Jumbo Hotfix Accumulator Take 230 (TGZ)
R80.10 Jumbo Hotfix Accumulator Take 298 (TGZ)
R77.30 Jumbo Hotfix Accumulator Take 351 (TGZ)
R77.30 Jumbo Hotfix Accumulator Take 338 (TGZ)
Quantum Maestro and Quantum Scalable Chassis
R80.30SP Jumbo Hotfix Accumulator Take 97 (TGZ)
R80.20SP Jumbo Hotfix Accumulator Take 336 (TGZ)
Quantum Spark Appliances
See sk182357: Preventative Hotfix for CVE-2024-24919 - Quantum Spark Gateways

For manual hotfix installation instructions on Quantum Security Gateways, see: sk168597 - How to install a Hotfix.

Automatic interim preventative measure deployed through AutoUpdater utility

Security Gateways that were configured to the Check Point's Auto Update process are gradually receiving an update (as of June 2, 2024), which helps protect them from various attempts to exploit the CVE. This is an interim preventative measure until the Hotfix is fully installed on customers' Security Gateways. It is important to emphasize that installing the Hotfix is the best way to stay protected from this vulnerability.

How to configure Auto Update on your Security Gateways:

Auto Update is enabled by default on all Security Gateways. To verify that it is enabled:

  1. In SmartConsole top-left corner, click the Menu button.
  2. Click Global properties.
  3. In the Data Access Control pane, select these checkboxes:
  1. Click OK
  2. Install the Access Control policy
  1. In SmartConsole top left-corner, click the Menu button.
  2. Click Global properties.
  3. In the Security Management pane, select the " Automatically download and install Blade Contracts, new software, and other important data (highly recommended)" checkbox.
  4. Click OK
  5. Install the Access Control policy

For more information, refer to:

Note: If Automatic Update is not possible, you can download and install the interim mitigation fix (VPNF) from sk182376. This SK article also contains all details about this Update.

Important extra measures

  1. Change the password of the LDAP Account Unit

If a Security Gateway / Cluster is configured to use an LDAP Account Unit, we recommend changing the password of the LDAP account.

Instructions:

  1. Reset password of local accounts connecting to Remote Access VPN with password-only authentication

  2. In SmartConsole, open the Object Explorer (press the CTRL+E keys) > VPN Communities > Remote Access.

  3. In Participant User Group pane, select the relevant User group.

  4. In the User Group properties, edit the relevant User.

  5. In the User properties window, go to the Authentication page and for Check Point Password click Set new password.

  6. Click OK.

  7. Repeat this procedure for EVERY User with the 'Check Point Password' authentication in ALL User Groups in ALL Remote Access VPN Communities.

  8. Prevent Local Accounts from connecting to VPN with Password-Only Authentication

We recommend not to use local accounts that authenticate the Remote Access VPN users with password-only authentication. This section provides mitigation steps to discover and prevent such accounts from logging into the VPN.

Procedure:

  1. Download the archive check-for-local-users-with-password-only-authentication-v5.zip to your computer.

  2. Extract the check-for-local-users-with-password-only-authentication.sh script file from the archive to a local directory.

  3. Connect with SmartConsole to your Security Management Server (on a Multi-Domain Server, connect to any Domain Management Server).

  4. From the left navigation panel, go to Gateways & Servers view.

  5. Click the Security Management Server object.

  6. From the the top toolbar, click Scripts > Scripts Repository.

The Script Repository window opens.

  1. Add the downloaded script to the repository:

    1. From the top toolbar, click New.
  2. In the Name field, paste: Check for local users with password-only authentication

  3. Optional: In the Comment field, paste: sk182336

  4. Click Load from file > select the script file check-for-local-users-with-password-only-authentication.sh.

  5. Wait for the script content to appear.

  6. Click OK.

  7. Run the script:

    1. In the Script Repository window, select the newly added script.
  8. From the top toolbar, click Run.

  9. The Run 'Check for local users with password-only authentication' On '' window opens.

  10. Click Run.

  11. Close the Script Repository window.

  12. Wait a few seconds for the script to complete - see the SmartConsole bottom left corner.

  13. Get the script result:

  14. Analyze the script result.

  15. Install the Hotfix to block Local Accounts with Password-Only Authentication

Additional Frequently Asked Questions

  1. What are the suspect IP addresses used by threat actors to exploit the vulnerability?
5.188.218.0/23
23.227.196.88
23.227.203.36
31.134.0.0/20
37.9.40.0/21
37.19.205.180
38.180.54.104
38.180.54.168
45.135.1.0/24
45.135.2.0/23
45.155.166.0/23
46.59.10.72
46.183.221.194
46.183.221.197
61.92.2.219
64.176.196.84
68.183.56.130
82.180.133.120
85.239.42.0/23
87.206.110.89
88.218.44.0/24
91.132.198.0/24
91.218.122.0/23
91.245.236.0/24
103.61.139.226
104.207.149.95
109.134.69.241
112.163.100.151
132.147.86.201
146.70.205.62
146.70.205.188
146.185.207.0/24
149.88.22.67
154.47.23.111
156.146.56.136
158.62.16.45
162.158.162.254
167.61.244.201
167.99.112.236
178.236.234.123
183.96.10.14
185.213.20.20
185.217.0.242
192.71.26.106
193.233.128.0/22
193.233.216.0/21
195.14.123.132
198.44.211.76
203.160.68.12
217.145.225.0/24
221.154.174.74
  1. When were exploitation attempts for this vulnerability first seen?

Our retrospective telemetry analysis shows exploitation attempts starting on 30 April 2024. Further investigation (as of 31 May 2024) revealed that the first exploitation attempts started on 07 April 2024. We are actively investigating further.

  1. What is the current CVSS score of this vulnerability?

As of 30 May 2024, the CVSS score is 8.6 (High), with the vector string - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Parameter Value Explanation
Attack Vector (AV) Network This vulnerability is exploited only through the Network.
Attack Complexity (AC) Low An attacker can expect repeatable success when attacking the vulnerable component. There are no special conditions or circumstances required for exploit success, assuming the component (VPN) is enabled on the Security Gateway.
Privilege Required (PR) None The attacker is unauthorized.
User Interaction (UI) None The vulnerability can be exploited without any user interaction.
Scope (S) Changed An exploited vulnerability can affect Security Gateway components besides the VPN.
Confidentiality (C) High All resources within the Security Gateway are potentially accessible to the attacker and are therefore considered compromised.
Integrity (I) None There is no loss of Security Gateway integrity.
Availability (A) None There is no impact on the Security Gateway availability.
  1. What is the recommendation for a Gateway running an End-of-Support version (R80.30 and lower)?

If you run a version that is already End-of-Support, we recommend one of these options:

  1. Is there an IPS Signature that can prevent attempts to exploit CVE-2024-24919?

Yes. The IPS Signature "Check Point VPN Information Disclosure (CVE-2024-24919)" detects and blocks attempts to exploit this CVE.

  1. If I suspect unauthorized access attempts, what should I do?

To investigate for suspicious activity, we recommend taking these steps:

  1. I have installed the hotfix "Hardening Remote Access for VPN users". Are the Security Gateways still vulnerable to CVE-2024-24919?

As an initial step, deploy the hotfix for CVE-2024-24919 to address the vulnerability. Implement the additional protection measures if you have Remote Access VPN users who authenticate to the Security Gateway using only a password (see "Important extra measures").

Article Revision History

Date Description
15 May 2025 Updated Important extra measures:
- Added the procedure "Renew the VPN default certificate / Multi-Portal certificate on the Security Gateway"
- Added the procedure "Renew the 3rd-party certificates for Multi-Portal of each applicable Software Blade on the Security Gateway"
25 June 2024 Updated Important extra measures:
1. Change the password for Gaia OS scheduled snapshots
2. Change the password for Gaia OS scheduled backups
3. Change the SNMP authentication settings
4. On a Standalone server, change the destination certificates for Log Exporter
5. Change the certificates for Identity Broker on the PDP Gateway
16 Jun 2024 - R81 Jumbo Hotfix Accumulator Take 99 was declared as Recommended
13 June 2024 Updated Important extra measures:
1. Change the shared secret in the RADIUS Server settings
2. Change the shared secret in the TACACS+ Server settings
10 June 2024 1. Added Hotfix for R77.30 Jumbo Hotfix Accumulator Take 338
2. R81.20 Jumbo Hotfix Accumulator Take 65 and R81.10 Jumbo Hotfix Accumulator Take 150 were declared as Recommended
06 June 2024 - Added "Update Azure HA Credentials" to the "Important extra measures" section
05 June 2024 1. Added R81 Jumbo Hotfix Accumulator Take 99
2. Updated the Procedure to identify vulnerable Security Gateways > Get the script results > Manual Check specifications section
3. Added Hotfix for R77.30 Jumbo Hotfix Accumulator Take 351
4. Added a note and link to sk182376 - Interim preventative measure (VPNF) for CVE-2024-24919
04 June 2024 - Updated the "Procedure to identify vulnerable Security Gateways" section
03 June 2024 1. Added instruction "How to configure Auto Update on your Security Gateways"
2. Added R81.20 Jumbo Hotfix Accumulator Take 65
02 June 2024 1. Added the "Automatic interim preventative measure deployed through AutoUpdater utility section
2. Added the "Install Jumbo Hotfix Accumulator to fix CVE-2024-24919" section and R81.10 Jumbo Hotfix Accumulator Take 150
01 June 2024 1. Added caution for customers using CCCD in R81.10 / R81.20
2. Added the "Article Revision History" section