The Cybersecurity and Infrastructure Security Agency has added a critical Check Point VPN vulnerability, identified as CVE-2024-24919, to its Known Exploited Vulnerabilities catalog. This information disclosure flaw impacts Check Point security gateways configured with Remote Access VPN or Mobile Access software. Federal agencies have been directed to apply the necessary security updates within a three-day window to mitigate the risk of unauthorized access to sensitive network environments.
Investigations indicate the vulnerability has been utilized as a zero-day by various threat actors, specifically including affiliates of the Qilin ransomware gang. The flaw allows attackers to access information on gateways connected to the internet, which can facilitate lateral movement within corporate networks. Check Point has confirmed that the exploit targets instances where local accounts use password-only authentication, as the missing security patch enables the retrieval of sensitive files from the gateway.
In response to these findings, Check Point released an emergency hotfix to address the security gap. The vendor reports that the vulnerability stems from the ability to read certain information on the gateway, which can then be leveraged by attackers to compromise accounts. Organizations using these specific Check Point configurations are advised to verify their gateway logs for suspicious activity and transition toward more robust authentication methods as part of their remediation strategy.
For enterprise IT leaders and service providers, this development emphasizes the immediate necessity of securing remote access infrastructure against credential-based attacks. The prioritization of this patch by CISA highlights the ongoing targeting of VPN appliances by sophisticated ransomware operations. Maintaining visibility into gateway logins and ensuring all security gateways are updated to the latest firmware remains critical for protecting organizational perimeters.
The BroadVision view
The inclusion of this Check Point vulnerability in the CISA catalog indicates a confirmed security risk for remote access gateways. Mid-market IT teams must prioritize immediate patching of affected security appliances to mitigate the risk of unauthorized network entry. Regular assessment of perimeter infrastructure helps organizations maintain alignment with evolving security standards. Explore strategic IT services for infrastructure governance
