Hermes CTI

← Back to all reports

vulnerability new

CVE-2024-24919

● HIGH Confidence: 100% · Version 1

Executive summary

Public evidence documents CVE-2024-24919. This report does not assess any organization.

Technical analysis

Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.

Evidence and sources

Public evidence for CVE-2024-24919 with preserved provenance.

Authoritative Source Advisories
Verified Evidence Claims

CVE-2024-24919 Check Point Quantum Security Gateways Information Disclosure Vulnerability Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.

100% Confidence Analysis 🔍

IOCs

No public IOC is available.

CVEs and affected products

Check Point Quantum Security Gateways Information Disclosure Vulnerability

ATT&CK mapping

No ATT&CK mapping is available.

Detection content

Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.

Open dedicated detections page →

Threat hunting

Hypothesis-driven hunt procedures and telemetry checklist.

Open dedicated hunt page →

Remediation

Containment actions, patching notes, and credential steps.

Open dedicated remediation page →

Historical relationships

No published historical relationship is available.

Timeline and change history

Public source record: Public source record for CVE-2024-24919.

Confidence and caveats

1.0

⚠️ Public CTI only; no organizational exposure is asserted.

⚠️ CVSS and EPSS metadata were not present in the retrieved evidence payload.