CVE-2024-24919Check Point Security Gateway information disclosure of password hashes
What broke
Check Point Security Gateways (including VPN and firewall blades) exposed files that contained password hashes to an unauthenticated caller. Those hashes include local admin and, in some configurations, VPN user material. CISA added CVE-2024-24919 to KEV. Check Point shipped a hotfix in late May 2024. Exploitation followed.
Why it matters
A VPN gateway is an identity provider for remote access. Leaking its hashes is credential theft at the enforcement point, after which MFA on the same box may not save you if the attacker cracks a local account or replays a legacy hash. Same product class as Ivanti Connect Secure and FortiCloud SSO.
What to do
- Apply the Check Point hotfix. If the gateway was internet-facing in May 2024, rotate local admin and VPN credentials and review logs for unexpected reads of the leaked paths.
- Move VPN users onto phishing-resistant MFA that does not share a hash file with the appliance OS.
- Do not leave the management or information-leak paths on the same interface as the VPN.
After you patch
Edge appliances sit outside the estate and hold credentials into it, which is why this class keeps producing multi-victim campaigns.
- Revoke all sessions on the appliance, then rotate the directory or LDAP service account it uses for authentication.
- Rotate certificates and any stored integration credentials, since configuration stores on these devices are a routine post-exploitation target.
- Hunt for authenticated sessions with no matching interactive login, and for logins from ASNs that had never appeared before the disclosure date.
- Check downstream: anything the appliance could reach or authenticate to is in scope, including SSO-connected applications.
Sources
- NVD: CVE-2024-24919
- CISA KEV
- Check Point sk182337 / May 2024 hotfix
Related identity CVEs
Related on Start with Identity
- CVEIvanti Connect Secure authentication bypass
Connect Secure and Policy Secure skipped authentication on a path that later chained with CVE-2024-21887 for unauthenticated RCE. CISA KEV. January 2024 disclos
- CVEJetBrains TeamCity 2024 authentication bypass, admin access
Unauthenticated attacker becomes a TeamCity administrator on on-prem instances. CVSS 9.8. Widely exploited. CISA KEV. The 2024 sequel to CVE-2023-42793, and the
- CVEN-able N-central auth bypass, incomplete patch of CVE-2026-18556
N-able N-central authentication bypass and account takeover. The first fix (CVE-2026-18556) was incomplete. Actively exploited. CISA added it to KEV on 3 August
- GlossaryZTNA
Zero Trust Network Access. The product category that replaces VPNs with identity-aware proxies. ZTNA grants access to specific applications based on identity an
- BlogA Check Point SmartConsole flaw hands out full admin tokens to unauthenticated attackers
CVE-2026-16232 (CVSS 9.3) lets an unauthenticated remote attacker obtain an application login token for Check Point Security Management and Multi-Domain Managem
- VendorPerimeter 81 (Check Point)
strong_contender