ZeroHour

CVE-2024-24919

KEV ransomwarelarge

Information Disclosure in Internet-Facing Check Point Quantum Security Gateways

CISA: Check Point Quantum Security Gateways Information Disclosure Vulnerability

CVSS 3.1
8.6 high
EPSS
100%p100
Published
()
KEV added
AI analysis

Check Point Quantum Security Gateways contain an information disclosure flaw (CWE-200) that can expose information stored on the appliance to unauthorized parties. It is triggered when an attacker targets a gateway connected to the internet with IPSec VPN, Remote Access VPN, or Mobile Access enabled, sending crafted requests to the exposed VPN services. A successful attacker gains unauthorized access to information on the gateway, and CISA notes known use of this flaw in ransomware campaigns. The issue spans multiple Check Point product lines: CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2024-05-30 with ransomware use listed, and EPSS assigns a 100% probability of exploitation within 30 days, though no public proof-of-concept is known.

What to do: Apply the hotfix Check Point distributes per its advisory (SK170863) to all internet-facing gateways running IPSec VPN, Remote Access VPN, or Mobile Access; this is also the CISA KEV required action. Where the hotfix cannot be applied immediately, restrict or disable the Remote Access VPN and Mobile Access software blades as an interim mitigation. Review gateway and VPN logs for signs of exploitation and prioritize remediation given confirmed ransomware use.

Affected
Check Point Quantum Security Gateways
Check Point CloudGuard Network
Check Point Quantum Scalable Chassis
Check Point Quantum Spark Appliances
Estimated exposure
largetens of thousands of internet-exposed VPN gateways (10k-100k systems) — Check Point is one of the most widely deployed enterprise edge firewall/VPN vendors, and public internet scans routinely surface tens of thousands of Check Point gateways; only internet-facing gateways with remote-access VPN blades enabled…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

CISA Known Exploited Vulnerability
Affected
Check Point Quantum Security Gateways
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
checkpoint
Products
quantum spark firmware, quantum security gateway firmware, cloudguard network security
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI and Lumen disrupted QTFY's QScan and QTRouter botnet platforms used by Chinese state-sponsored hackers to conceal intrusions into U.S. agencies.

The U.S. DoJ announced court-authorized seizure of domains behind QScan and QTRouter, operated by the Chinese state-sponsored group QTFY and employed by Nanjing Xinjiuwei Network Technology Company. QTFY has been active since May 2018 and targeted NASA, the Federal Reserve, the Department of Energy, DoJ, HHS, NIH, the U.S. Senate, and academic institutions. QScan exploits vulnerable IoT devices, feeding them into QTRouter, an OpenWrt-based proxy obfuscation network likened to an operational relay box (ORB) that masks attack origins. The group exploited zero-days such as Ivanti CSA flaws CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380, plus numerous N-days, and maintained persistence with RATs, web shells, and legitimate credentials.

The Hacker News · 13d agoThreat actor in the wildCVE-2018-13379CVE-2019-10068CVE-2019-19781+10 CVEs