CVE-2024-24919

ENISA EUVD: EUVD-2024-22282 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 10 articles Published: 2024-05-28

EPSS Score

Source: FIRST.org · 2026-05-24
94.39%
probability
This CVE has a 94.39% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
8.6
HIGH
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Description

VulnerabilityLookup (CNA)
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

Affected Products

checkpoint
Check Point Quantum Gateway, Spark Gateway and CloudGuard Network
Check Point Quantum Gateway and CloudGuard Network versions R81.20, R81.10, R81, R80.40 and Check Point Spark versions R81.10, R80.20.

Attack Intelligence

Exploits & PoC

seed1337/CVE-2024-24919-POC

PoC CVE-2024-24919 — seed1337/CVE-2024-24919-POC

47
ifconfig-me/CVE-2024-24919-Bulk-Scanner

CVE-2024-24919 [Check Point Security Gateway Information Disclosure]

31
RevoltSecurities/CVE-2024-24919

An Vulnerability detection and Exploitation tool for CVE-2024-24919

25
GoatSecurity/CVE-2024-24919

CVE-2024-24919 exploit

19
un9nplayer/CVE-2024-24919

This repository contains a proof-of-concept (PoC) exploit for CVE-2024-24919, a critical vulnerability discovered in Check Point SVN. The vulnerabilit

16
LucasKatashi/CVE-2024-24919

CVE-2024-24919 Exploit PoC

12
0nin0hanz0/CVE-2024-24919-PoC

PoC CVE-2024-24919 — 0nin0hanz0/CVE-2024-24919-PoC

11
verylazytech/CVE-2024-24919

POC - CVE-2024–24919 - Check Point Security Gateways

9
geniuszly/CVE-2024-24919

PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing se

6
9 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 94.39%
CVSS v3.1 8.6
Mentions 10
Last Seen Feb 25, 2025

CNA Information

CNA Assigner
checkpoint
CNA Title
Information disclosure

Analyst Note

CVE-2024-24919 meets all zero-day criteria: exploitation in the wild is explicitly documented (attacks since April 30, 2024), the CVE was published May 28, 2024, and authoritative sources (BleepingComputer, CERT-EU) explicitly label it as a zero-day with emergency patching. Exploitation clearly preceded or occurred contemporaneously with patch availability.

Threat Actors 41

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
APT 29
apt_group Information theft and espionage 🇷🇺 RU
DarkHotel
apt_group Information theft and espionage 🇰🇷 KR
Mustang Panda
apt_group Information theft and espionage 🇨🇳 CN
Cobalt
apt_group Financial crime 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Harvester
apt_group Information theft and espionage Unknown
Hacking Team
apt_group 🇮🇹 IT
Chamelgang
apt_group Information theft and espionage 🇨🇳 CN
Sea Turtle
apt_group Information theft and espionage 🇹🇷 TR
Tick
apt_group Information theft and espionage 🇨🇳 CN
APT3
apt_group Information theft and espionage 🇨🇳 CN
Infy
apt_group Information theft and espionage 🇮🇷 IR
Volt Typhoon
apt_group Information theft and espionage 🇨🇳 CN
Group 27
apt_group Information theft and espionage 🇨🇳 CN
ArcaneDoor
apt_group 🇨🇳 CN
APT-C-36
apt_group Information theft and espionage 🇨🇴 CO
Silence group
apt_group Financial crime 🇷🇺 RU
APT42
apt_group Information theft and espionage 🇮🇷 IR
Storm-2077
apt_group Information theft and espionage 🇨🇳 CN
TAG-100
apt_group Information theft and espionage 🇨🇳 CN
Fox Kitten
apt_group Information theft and espionage 🇮🇷 IR
Returned Libra
apt_group 🇨🇳 CN
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Rocke
apt_group 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Bitwise Spider
apt_group Financial gain 🇷🇺 RU
Red Dev 17
apt_group 🇨🇳 CN
CoreInjection
apt_group 🇮🇱 IL
Red October
apt_group 🇷🇺 RU
Circles
apt_group Global
Operation Digital Eye
apt_group Information theft and espionage 🇨🇳 CN
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Iron Group
apt_group Information theft and espionage 🇨🇳 CN
Operation ShadowHammer
apt_group 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime
Operation Crimson Palace
apt_group Information theft and espionage 🇨🇳 CN
Dark Partners
apt_group

Triage Info

Decided atMar 05, 2026
Published DateMay 28, 2024