sk182357 - Preventative Hotfix for CVE-2024-24919 - Spark Firewall
Preventative Hotfix for CVE-2024-24919 - Spark Firewall
Please read this important update from Check Point.
Security Alert:
High
Product: Spark Firewall
Version: R77.20 (EOS), R80.20.X (EOS), R81.10.X
OS: Gaia Embedded
Last Modified: 2025-02-23
Solution
For Security Gateways that run the Gaia OS, refer to sk182336: Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure.
Following our security update on May 27, 2024, Check Point's dedicated task force continues investigating attempts to gain unauthorized access to VPN products used by our customers. On May 28, 2024 we discovered a vulnerability (CVE-2024-24919) in Security Gateways with Remote Access VPN or the Mobile Access software blade enabled. Exploiting this vulnerability can result in accessing sensitive information on the Security Gateway.
This, in certain scenarios, can potentially lead the attacker to move laterally and gain domain admin privileges.
If you need any additional assistance, contact Check Point Support or your local Check Point representative.
Quantum Spark Gateway images that include the mandatory Hotfix to prevent exploit of CVE-2024-24919
| Firmware Version | Minimum Required Build | SK Article |
| R81.10.15 (and higher) | Build 996003913 | See sk182438 |
| R81.10.10 | Build 996002945 | See sk181080 |
| R81.10.08 | Build 996001750 | See sk181079 |
| R80.20.60 | Build 992002903 | See sk179922 |
| R77.20.87 | Build 990173160 | See sk151574 |
| R77.20.81 | Build 990172628 | See sk137212 |
Step 1 of 3 - Check the current firmware build on your Quantum Spark Gateway
- Connect to the WebUI on the Quantum Spark Gateway from a computer on an internal network:
https://<IP Address of Appliance>:4434
Example: https://192.168.1.1:4434
- On the left panel, click the Home view.
- In the Overview section, click the System page.
- Below the hostname, refer to the field Version.
Example:
Step 2 of 3 - Upgrade your Quantum Spark Gateway to an image that includes the mandatory Hotfix to prevent exploit of CVE-2024-24919
Note - If your Quantum Spark Gateway already runs one of the mandatory firmware images, then it is not necessary to upgrade again, unless you received a private firmware build from Check Point Support (the private firmware build must be greater than the mandatory build listed above).
- Download the mandatory firmware image from the corresponding Home Page SK article (see the summary table above).
- Follow the R81.10.X Quantum Spark Locally Managed Administration Guide > chapter "Managing the Device" > section "Backup, Restore, Upgrade, and Other System Operations".
Step 3 of 3 - Follow the important extra measures
- Disable the Remote Access VPN blade
- If you do not use the Remote Access VPN feature, then disable it:
- Click the VPN view.
- In the Remote Access section, click Blade Control.
- At the top of the page, click Off.
- Change the passwords for administrator users (and use complex passwords) and local users
- Restrict access through "Reach My Device"
- Enable Two-Factor Authentication for Administrators (R81.10.10 and higher)
- Enable notifications for administrator access
- Reinitialize Internal Certificate Authority (CA)
- Change the shared secret in the RADIUS Server settings
- Change the shared secret in the TACACS+ Server settings
- Change the password in the Active Directory server settings
- Change the password in the Wireless settings
Article Revision History
| Date | Description |
|---|---|
| 15 July 2024 | Corrected the sentence from "On May 28, 2024 we discovered a vulnerability in Security Gateways with IPsec VPN in Remote Access VPN community and the Mobile Access software blade (CVE-2024-24919)." to "On May 28, 2024 we discovered a vulnerability (CVE-2024-24919) in Security Gateways with Remote Access VPN or the Mobile Access software blade enabled." |
| 07 July 2024 | Updated passwords and user management steps in the guide. |
| 13 June 2024 | Added the steps to check the current firmware build. |
| 06 June 2024 | Removed irrelevant information in Upgrade instructions. |
| 03 June 2024 | Added steps for certificate authority, RADIUS, TACACS+, etc. |
| 01 June 2024 | First release of this article. |