# Check Point Response to CVE-2024-24911 - Out of Bounds read in the CPCA process on a Check Point Management Server

Please read this important update from Check Point.

**Security Alert:**

- **Medium**

**Product**: Multi-Domain Security Management, Security Management  
**Version**: R81 (EOS), R81.10 (EOS), R81.20, R82  
**OS**: Gaia  
**Last Modified**: 2025-02-10

## Symptoms

- In rare scenarios, the `cpca` process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file.
- When the `cpca` process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL cache, and a certificate needs to be verified by the `cpca` process on the Management Server.

This issue received the ID [CVE-2024-24911](https://www.cve.org/CVERecord?id=CVE-2024-24911).

## Cause

An Out-of-Bounds read may occur when processing certain HTTP "POST" requests to the Security Management Server / Domain Management Server to the TCP port 18264.

Repeated requests can cause a denial-of-service (DoS) of the `cpca` process and may lead it to exit unexpectedly with a core dump file.

## Solution

This problem was fixed on the Check Point Management Server.

The fix is included starting from:

- [Check Point R82](https://support.checkpoint.com/results/sk/sk181127)
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 79
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 158
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 106

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

- **Access Level**: General  
- **Severity**: Medium  
- **Status**: Approved by TAC  
- **Date Created**: 2025-02-02  
- **Last Modified**: 2025-02-10
