By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Check Point releases emergency fix for VPN zero-day exploited in attacks
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Check Point releases emergency fix for VPN zero-day exploited in attacks
Tech News

Check Point releases emergency fix for VPN zero-day exploited in attacks

By admin 3 Min Read
Share
SHARE

Check Point has released hotfixes for a VPN zero-day vulnerability exploited in attacks to gain remote access to firewalls and attempt to breach corporate networks.

On Monday, the company first warned about a spike in attacks targeting VPN devices, sharing recommendations on how admins can protect their devices. Later, it discovered the source of the problem, a zero-day flaw that hackers exploited against its customers.

Tracked as CVE-2024-24919, the high-severity information disclosure vulnerability enables attackers to read certain information on internet-exposed Check Point Security Gateways with remote Access VPN or Mobile Access Software Blades enabled.

“The vulnerability potentially allows an attacker to read certain information on Internet-connected Gateways with remote access VPN or mobile access enabled,” reads an update on Check Point’s previous advisory.

“The attempts we’ve seen so far, as previously alerted on May 27, focus on remote access scenarios with old local accounts with unrecommended password-only authentication.”

CVE-2024-24929 impacts CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances, in the product versions: R80.20.x, R80.20SP (EOL), R80.40 (EOL), R81, R81.10, R81.10.x, and R81.20.

Check Point has released the following security updates to address the flaw:

  • Quantum Security Gateway and CloudGuard Network Security: R81.20, R81.10, R81, R80.40
  • Quantum Maestro and Quantum Scalable Chassis: R81.20, R81.10, R80.40, R80.30SP, R80.20SP
  • Quantum Spark Gateways: R81.10.x, R80.20.x, R77.20.x

To apply the update, head to the Security Gateway portal > Software Updates > Available Updates > Hotfix Updates, and click ‘Install.’

The vendor says the process should take approximately 10 minutes, and a reboot is required.

Applying the update through the panel
<strong>Applying the update through the panel</strong><br /><em>Source: Check Point</em>

After the hotfix is installed, login attempts using weak credentials and authentication methods will be automatically blocked, and a log will be created.

Blocked login attempt
<strong>Blocked login attempt</strong><br /><em>Source: Check Point</em>

Hotfixes have been made available for end-of-life (EOL) versions, too, but they must be downloaded and applied manually.

Check Point created a FAQ page with additional information about CVE-2024-24919, IPS signature, and manual hotfix installation instructions.

Those unable to apply the update are advised to enhance their security stance by updating the Active Directory (AD) password that the Security Gateway uses for authentication.

Additionally, Check Point has created a remote access validation script that can be uploaded onto ‘SmartConsole’ and executed to review the results and take appropriate actions.

More information on updating the AD password and using the ‘VPNcheck.sh’ script are available on Check Point’s security bulletin.

You Might Also Like

CISA flags Windows Task Host vulnerability as exploited in attacks

Anthropic sets sights on small business after enterprise push

Sony Xperia 1 VIII AI Camera Assistant Internet Outrage

How to Control Everything on Your Phone With Your Voice (iOS and Android)

Critical Nginx UI auth bypass flaw now actively exploited in the wild

TAGGED: Actively Exploited, Check Point Software, Information Disclosure, VPN, Vulnerability, Zero-Day
Share This Article
Facebook Twitter Copy Link
Previous Article Viral Meme Coin, Memeinator, Lists On Exchanges After Raising $7.7M
Next Article KVM Monitors Let You Cut Down the Desk Clutter, and I Love It
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

CISA flags Windows Task Host vulnerability as exploited in attacks
Tech News
Aaron Rodgers Will Reportedly Return to Steelers, Agrees To 1-Year Deal
Sports
French judge opens probe into 2018 killing of Jamal Khashoggi
World News
Bitcoin Treasury Firm Strategy To Repurchase $1.5B Of Convertible Notes — Details
Crypto
Forza Horizon 6 Lets You Race A Gundam And It Looks Awesome
Gaming News
Hushpitality, inheritourism and US road trips: These are all the 2026 travel trends you need to know
Travel
Good time to fill up on fuel as prices set to jump – Why, and by how much?
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Aaron Rodgers Will Reportedly Return to Steelers, Agrees To 1-Year Deal

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Aaron Rodgers Will Reportedly Return to Steelers, Agrees To 1-Year Deal
May 17, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?