sk182357 - Preventative Hotfix for CVE-2024-24919 - Spark Firewall

Preventative Hotfix for CVE-2024-24919 - Spark Firewall

Please read this important update from Check Point.

Security Alert:

High

Product: Spark Firewall
Version: R77.20 (EOS), R80.20.X (EOS), R81.10.X
OS: Gaia Embedded
Last Modified: 2025-02-23

Solution

For Security Gateways that run the Gaia OS, refer to sk182336: Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure.

Following our security update on May 27, 2024, Check Point's dedicated task force continues investigating attempts to gain unauthorized access to VPN products used by our customers. On May 28, 2024 we discovered a vulnerability (CVE-2024-24919) in Security Gateways with Remote Access VPN or the Mobile Access software blade enabled. Exploiting this vulnerability can result in accessing sensitive information on the Security Gateway.

This, in certain scenarios, can potentially lead the attacker to move laterally and gain domain admin privileges.

If you need any additional assistance, contact Check Point Support or your local Check Point representative.

Quantum Spark Gateway images that include the mandatory Hotfix to prevent exploit of CVE-2024-24919

Firmware Version Minimum Required Build SK Article
R81.10.15 (and higher) Build 996003913 See sk182438
R81.10.10 Build 996002945 See sk181080
R81.10.08 Build 996001750 See sk181079
R80.20.60 Build 992002903 See sk179922
R77.20.87 Build 990173160 See sk151574
R77.20.81 Build 990172628 See sk137212

Step 1 of 3 - Check the current firmware build on your Quantum Spark Gateway

  1. Connect to the WebUI on the Quantum Spark Gateway from a computer on an internal network:

https://<IP Address of Appliance>:4434

Example: https://192.168.1.1:4434

  1. On the left panel, click the Home view.
  2. In the Overview section, click the System page.
  3. Below the hostname, refer to the field Version.

Example:

Step 2 of 3 - Upgrade your Quantum Spark Gateway to an image that includes the mandatory Hotfix to prevent exploit of CVE-2024-24919

Note - If your Quantum Spark Gateway already runs one of the mandatory firmware images, then it is not necessary to upgrade again, unless you received a private firmware build from Check Point Support (the private firmware build must be greater than the mandatory build listed above).

  1. Download the mandatory firmware image from the corresponding Home Page SK article (see the summary table above).
  2. Follow the R81.10.X Quantum Spark Locally Managed Administration Guide > chapter "Managing the Device" > section "Backup, Restore, Upgrade, and Other System Operations".

Step 3 of 3 - Follow the important extra measures

  1. Disable the Remote Access VPN blade

Article Revision History

Date Description
15 July 2024 Corrected the sentence from "On May 28, 2024 we discovered a vulnerability in Security Gateways with IPsec VPN in Remote Access VPN community and the Mobile Access software blade (CVE-2024-24919)." to "On May 28, 2024 we discovered a vulnerability (CVE-2024-24919) in Security Gateways with Remote Access VPN or the Mobile Access software blade enabled."
07 July 2024 Updated passwords and user management steps in the guide.
13 June 2024 Added the steps to check the current firmware build.
06 June 2024 Removed irrelevant information in Upgrade instructions.
03 June 2024 Added steps for certificate authority, RADIUS, TACACS+, etc.
01 June 2024 First release of this article.