# Preventative Hotfix for CVE-2024-24919 - Spark Firewall

Please read this important update from Check Point.

Security Alert:

High

Product: Spark Firewall  
Version: R77.20 (EOS), R80.20.X (EOS), R81.10.X  
OS: Gaia Embedded  
Last Modified: 2025-02-23

## Solution

**For Security Gateways that run the Gaia OS, refer to [sk182336: Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure](https://support.checkpoint.com/results/sk/sk182336)**.

Following our security update on May 27, 2024, Check Point's dedicated task force continues investigating attempts to gain unauthorized access to VPN products used by our customers. On May 28, 2024 we discovered a vulnerability (CVE-2024-24919) in Security Gateways with Remote Access VPN or the Mobile Access software blade enabled. Exploiting this vulnerability can result in accessing sensitive information on the Security Gateway.

This, in certain scenarios, can potentially lead the attacker to move laterally and gain domain admin privileges.

If you need any additional assistance, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) or your local Check Point representative.

### Quantum Spark Gateway images that include the mandatory Hotfix to prevent exploit of CVE-2024-24919

|     |     |     |
| --- | --- | --- |
| Firmware Version | Minimum Required Build | SK Article |
| **R81.10.15 (and higher)** | Build 996003913 | See [sk182438](https://support.checkpoint.com/results/sk/sk182438) |
| **R81.10.10** | Build 996002945 | See [sk181080](https://support.checkpoint.com/results/sk/sk181080#Downloads) |
| **R81.10.08** | Build 996001750 | See [sk181079](https://support.checkpoint.com/results/sk/sk181079#Downloads) |
| **R80.20.60** | Build 992002903 | See [sk179922](https://support.checkpoint.com/results/sk/sk179922#Downloads) |
| **R77.20.87** | Build 990173160 | See [sk151574](https://support.checkpoint.com/results/sk/sk151574#Downloads) |
| **R77.20.81** | Build 990172628 | See [sk137212](https://support.checkpoint.com/results/sk/sk137212#Downloads) |

### Step 1 of 3 - Check the current firmware build on your Quantum Spark Gateway

1. Connect to the WebUI on the Quantum Spark Gateway from a computer on an internal network:

`https://<IP Address of Appliance>:4434`

Example: _https://192.168.1.1:4434_

2. On the left panel, click the **Home** view.
3. In the **Overview** section, click the **System** page.
4. Below the hostname, refer to the field **Version**.

Example:

### Step 2 of 3 - Upgrade your Quantum Spark Gateway to an image that includes the mandatory Hotfix to prevent exploit of CVE-2024-24919

> **Note** - If your Quantum Spark Gateway already runs one of the mandatory firmware images, then it is **not** necessary to upgrade again, unless you received a private firmware build from Check Point Support (the private firmware build must be greater than the mandatory build listed above).
>
> 1. Download the mandatory firmware image from the corresponding Home Page SK article (see the summary table above).
> 2. Follow the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Backup-Restore-Upgrade-and-Other-System-Operatons.htm) > chapter "Managing the Device" > section "Backup, Restore, Upgrade, and Other System Operations".

### Step 3 of 3 - Follow the important extra measures

> 1. Disable the Remote Access VPN blade
>   - If you do not use the **Remote Access VPN** feature, then disable it:
>     1. Click the **VPN** view.
>     2. In the **Remote Access** section, click **Blade Control**.
>     3. At the top of the page, click **Off**.
>     > 
>     > 2. Change the passwords for administrator users (and use complex passwords) and local users
>     > 3. Restrict access through "Reach My Device"
>     > 4. Enable Two-Factor Authentication for Administrators (R81.10.10 and higher)
>     > 5. Enable notifications for administrator access
>     > 6. Reinitialize Internal Certificate Authority (CA)
>     > 7. Change the shared secret in the RADIUS Server settings
>     > 8. Change the shared secret in the TACACS+ Server settings
>     > 9. Change the password in the Active Directory server settings
>     > 10. Change the password in the Wireless settings

### Article Revision History

| Date          | Description |
|---------------|-------------|
| 15 July 2024 | Corrected the sentence from "On May 28, 2024 we discovered a vulnerability in Security Gateways with IPsec VPN in Remote Access VPN community and the Mobile Access software blade (CVE-2024-24919)." to "On May 28, 2024 we discovered a vulnerability (CVE-2024-24919) in Security Gateways with Remote Access VPN or the Mobile Access software blade enabled." |
| 07 July 2024 | Updated passwords and user management steps in the guide. |
| 13 June 2024 | Added the steps to check the current firmware build. |
| 06 June 2024 | Removed irrelevant information in Upgrade instructions. |
| 03 June 2024 | Added steps for certificate authority, RADIUS, TACACS+, etc. |
| 01 June 2024 | First release of this article.
