Description |
Check Point Security Gateways has an information disclosure vulnerability which allows for an unauthenticated threat actor to read the contents files located on the affected appliance. Threat actor could abuse CVE-2024-24919 to read password hashes for local accounts on the appliance. Accounts with weak password can be compromised leading to further exploitation and potential lateral movement. |
||||||
CVE ID |
CVE-2024-24919 (https://nvd.nist.gov/vuln/detail/CVE-2024-24919) |
||||||
NDR Cloud Detection Rule |
FortiNDR Cloud v2024.5+
|
||||||
Playbook | N/A | ||||||
Threat Hunting |
FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for “Check Point Quantum Security Gateways Information Disclosure Attack” related activities |
||||||
Suricata Coverage |
Customers can create custom investigation/detections using the Suricata signatures below |
||||||
Other Fortinet Products |
For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.