"PoC Published for Exploited Check Point VPN Vulnerability"
"PoC Published for Exploited Check Point VPN Vulnerability"
Proof-of-concept (PoC) code has recently been released for an actively exploited zero-day vulnerability affecting multiple Check Point Security Gateway iterations. The vulnerability was disclosed on May 27 and is tracked as CVE-2024-24919 (CVSS score of 8.6). The issue is described as an arbitrary file read issue in gateways that have IPSec VPN or Mobile Access blades enabled. According to Check Point, its CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security gateways, and Quantum Spark appliances are impacted.