A Zero-Day vulnerability in Check Point Security Gateway, a popular VPN solution, has been exploited by malicious actors. The vulnerability, identified as CVE-2024-24919, allows an attacker to bypass authentication and access sensitive information from the Gateway’s management interface.
According to Check Point, the vulnerability affects all Check Point Security Gateway products where any of the following are enabled:
• Mobile Access Software Blade
• IPsec VPN Blade
It is important to note that the vulnerability is relevant only in cases where one of the aforementioned software components was enabled as part of a Remote Access VPN community. Check Point researchers discovered the vulnerability after observing attack attempts against vendors. According to Check Point, attackers exploited the vulnerability to download configuration files, certificates, passwords, and other sensitive information from compromised Gateways. Attackers also attempted to execute commands on the Gateways but were blocked by the system’s self-defense mechanisms.
In response, Check Point published a security advisory including mitigation steps and a Hotfix. The company recommends that customers install the Hotfix as soon as possible and restrict management interface access to trusted networks only. Customers should also monitor their Gateways for any signs of breach and report any suspicious activity to Check Point.
CVE-2024-24919 poses a serious threat to the security and privacy of Check Point Security Gateway users. The vulnerability exposes Gateways to remote attacks and data leaks, and could enable further lateral movement or privilege escalation within the network. Customers must act quickly to protect their Gateways and prevent any damage from ongoing attacks.
Information Security Recommendations for Organizations regarding CVE-2024-24919 by IPV Security Experts:
- Immediate Implementation of Hotfix: The Hotfix provided by Check Point must be installed immediately. This is the primary line of defense against the exploitation of CVE-2024-24919. The Hotfix addresses the specific vulnerability allowing unauthorized access to the management interface.
- Restricting Management Interface Access: Network access control settings should be configured so that only trusted networks can access the Check Point Security Gateway management interface. Restricting access reduces the attack surface and prevents unauthorized users from exploiting the vulnerability.
- Monitoring and Auditing Gateway Activity: Logs of operations on Check Point Security Gateways should be continuously monitored and collected for any anomalous or suspicious behavior. Early detection of attack attempts enables a rapid response to mitigate damage. Particular attention should be paid to attempts to download configuration files, certificates, and passwords, or attempts to execute unauthorized commands.
- Implementing Network Segmentation: Network segmentation should be implemented to isolate critical systems and management interfaces from standard user networks and potential threat sources. Network segmentation limits the ability of attackers to move laterally within the network, thereby reducing the likelihood of potential breaches.
- Enhancing Security Response Capabilities: Ensure that security response teams are prepared to handle potential vulnerabilities in the Check Point Security Gateway. Security response plans specific to this scenario should be developed and practiced. A well-prepared security response team can quickly mitigate the impact of an attack and maintain the integrity and availability of network resources.
- Implementing the Principle of Least Privilege: Review and minimize the permissions of accounts that have access to the Check Point Security Gateway management interface. Reducing the number of highly privileged accounts and ensuring that users have only the necessary permissions reduces the impact of credential theft.
- Regular Patch Management Updates: Maintain an effective Patch Management process to ensure that all systems, especially security devices such as firewalls and VPNs, are up to date with the latest security patches. Regular updates and patches fix vulnerabilities that could be exploited by attackers and maintain the organization’s security posture.
- Staff Education and Training: Conduct training sessions for IT and security teams on the specific characteristics of CVE-2024-24919 and the importance of adhering to security best practices. A more aware staff is likely to identify and respond appropriately to potential security incidents, reducing the risk of successful attacks.
- Collaboration with Check Point: Contact Check Point support and cooperate by following their security advisories. Direct communication with the vendor ensures that organizations receive timely updates and critical information regarding security vulnerabilities and patches.
- Reporting Suspicious Activity: Any suspicious activity related to Check Point Security Gateways should be reported immediately to Check Point for further analysis and guidance. Incident reporting helps Check Point better understand the scope of threats and provide more effective support and updates.