Check Point disclosed and patched CVE-2024-24919, a critical information disclosure flaw affecting Internet-connected Network Security Gateway devices with Remote Access VPN or Mobile Access enabled. The vulnerability was traced to improper HTTP POST request validation that can enable directory traversal and arbitrary file reads by an unauthenticated attacker, allowing exposure of sensitive data from affected gateways. Check Point said it observed exploitation attempts in the wild, issued an initial mitigation, then released a mandatory hotfix and urged customers to apply it immediately.
Reported abuse focused on remote-access environments, particularly older local VPN accounts using password-only authentication. Stolen data may include local account password hashes, private SSH keys, certificates, and potentially Active Directory-related files such as ntds.dit, creating follow-on risk of credential theft, lateral movement, broader network intrusion, and possible escalation toward remote code execution. Check Point and external responders advised organizations to disable unused local accounts, enforce stronger authentication such as MFA or certificates, rotate exposed credentials, and review gateway and authentication logs for signs of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Check Point published guidance describing observed exploitation focused on remote-access scenarios using old local VPN accounts with password-only authentication, and said it was working with customers believed to be affected. It advised disabling unused local accounts and strengthening authentication, such as using certificates instead of password-only logins.
Check Point stated that it identified the root cause of CVE-2024-24919 and released a mandatory fix. The company also said it had observed exploitation attempts against a small number of customers.
Check Point said it delivered an initial mitigation for the VPN information disclosure vulnerability affecting Internet-connected Network Security gateways with Remote Access VPN or Mobile Access enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourceblog.checkpoint.com
Open sourcelabs.watchtowr.com
Open sourcesupport.checkpoint.com
Open sourcemnemonic.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.