Answer in brief
CVE-2024-24919 records a High severity vulnerability in Information disclosure. The current sources mark it as known exploited. The current feed maps checkpoint/Check Point Quantum Gateway, Spark Gateway and CloudGuard Network (generic), checkpoint/cloudguard_network (generic), checkpoint/quantum_security_gateway_firmware (generic), checkpoint/quantum_spark_appliances (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps checkpoint/Check Point Quantum Gateway, Spark Gateway and CloudGuard Network (generic), checkpoint/cloudguard_network (generic), checkpoint/quantum_security_gateway_firmware (generic), checkpoint/quantum_spark_appliances (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| checkpoint/Check Point Quantum Gateway, Spark Gateway and CloudGuard Networkgeneric | Check Point Quantum Gateway and CloudGuard Network versions R81.20, R81.10, R81, R80.40 and Check Point Spark versions R81.10, R80.20. | Not reported |
| checkpoint/cloudguard_networkgeneric | r80.40 || r81 || r81.10 || r81.20 | Not reported |
| checkpoint/quantum_security_gateway_firmwaregeneric | r80.40 || r81 || r81.10 || r81.20 | Not reported |
| checkpoint/quantum_spark_appliancesgeneric | r80.40 || r81 || r81.10 || r81.20 | Not reported |
Published upstream
May 28, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
May 30, 2024
Evidence: source:kev:kev:kev:recordPotentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-24919 records a High severity vulnerability in Information disclosure. The current sources mark it as known exploited. The current feed maps checkpoint/Check Point Quantum Gateway, Spark Gateway and CloudGuard Network (generic), checkpoint/cloudguard_network (generic), checkpoint/quantum_security_gateway_firmware (generic), checkpoint/quantum_spark_appliances (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps checkpoint/Check Point Quantum Gateway, Spark Gateway and CloudGuard Network (generic), checkpoint/cloudguard_network (generic), checkpoint/quantum_security_gateway_firmware (generic), checkpoint/quantum_spark_appliances (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| checkpoint/Check Point Quantum Gateway, Spark Gateway and CloudGuard Networkgeneric | Check Point Quantum Gateway and CloudGuard Network versions R81.20, R81.10, R81, R80.40 and Check Point Spark versions R81.10, R80.20. | Not reported |
| checkpoint/cloudguard_networkgeneric | r80.40 || r81 || r81.10 || r81.20 | Not reported |
| checkpoint/quantum_security_gateway_firmwaregeneric | r80.40 || r81 || r81.10 || r81.20 | Not reported |
| checkpoint/quantum_spark_appliancesgeneric | r80.40 || r81 || r81.10 || r81.20 | Not reported |
Published upstream
May 28, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
May 30, 2024
Evidence: source:kev:kev:kev:recordPotentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
Quoted source text, attributed separately from HOL analysis.