By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Check Point releases emergency fix for VPN zero-day exploited in attacks
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Check Point releases emergency fix for VPN zero-day exploited in attacks
Tech News

Check Point releases emergency fix for VPN zero-day exploited in attacks

By admin 3 Min Read
Share
SHARE

Check Point has released hotfixes for a VPN zero-day vulnerability exploited in attacks to gain remote access to firewalls and attempt to breach corporate networks.

On Monday, the company first warned about a spike in attacks targeting VPN devices, sharing recommendations on how admins can protect their devices. Later, it discovered the source of the problem, a zero-day flaw that hackers exploited against its customers.

Tracked as CVE-2024-24919, the high-severity information disclosure vulnerability enables attackers to read certain information on internet-exposed Check Point Security Gateways with remote Access VPN or Mobile Access Software Blades enabled.

“The vulnerability potentially allows an attacker to read certain information on Internet-connected Gateways with remote access VPN or mobile access enabled,” reads an update on Check Point’s previous advisory.

“The attempts we’ve seen so far, as previously alerted on May 27, focus on remote access scenarios with old local accounts with unrecommended password-only authentication.”

CVE-2024-24929 impacts CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances, in the product versions: R80.20.x, R80.20SP (EOL), R80.40 (EOL), R81, R81.10, R81.10.x, and R81.20.

Check Point has released the following security updates to address the flaw:

  • Quantum Security Gateway and CloudGuard Network Security: R81.20, R81.10, R81, R80.40
  • Quantum Maestro and Quantum Scalable Chassis: R81.20, R81.10, R80.40, R80.30SP, R80.20SP
  • Quantum Spark Gateways: R81.10.x, R80.20.x, R77.20.x

To apply the update, head to the Security Gateway portal > Software Updates > Available Updates > Hotfix Updates, and click ‘Install.’

The vendor says the process should take approximately 10 minutes, and a reboot is required.

Applying the update through the panel
<strong>Applying the update through the panel</strong><br /><em>Source: Check Point</em>

After the hotfix is installed, login attempts using weak credentials and authentication methods will be automatically blocked, and a log will be created.

Blocked login attempt
<strong>Blocked login attempt</strong><br /><em>Source: Check Point</em>

Hotfixes have been made available for end-of-life (EOL) versions, too, but they must be downloaded and applied manually.

Check Point created a FAQ page with additional information about CVE-2024-24919, IPS signature, and manual hotfix installation instructions.

Those unable to apply the update are advised to enhance their security stance by updating the Active Directory (AD) password that the Security Gateway uses for authentication.

Additionally, Check Point has created a remote access validation script that can be uploaded onto ‘SmartConsole’ and executed to review the results and take appropriate actions.

More information on updating the AD password and using the ‘VPNcheck.sh’ script are available on Check Point’s security bulletin.

You Might Also Like

Here’s What You Should Know About Launching an AI Startup

Sony Xperia 1 VII Review: When Unique Isn’t Enough

Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery

OpenCode Open Source TUI with LSP and Multi Session Control

React2Shell critical flaw actively exploited in China-linked attacks

TAGGED: Actively Exploited, Check Point Software, Information Disclosure, VPN, Vulnerability, Zero-Day
Share This Article
Facebook Twitter Copy Link
Previous Article Viral Meme Coin, Memeinator, Lists On Exchanges After Raising $7.7M
Next Article KVM Monitors Let You Cut Down the Desk Clutter, and I Love It
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Madison Prewett’s Husband: All About Grant Troutt & Her Post-‘Bachelor’ Life
Celebrity
Here’s What You Should Know About Launching an AI Startup
Tech News
Netflix cofounder started his career selling vacuums door-to-door before college—now, his $440 billion streaming giant is buying Warner Bros. and HBO
Business
Sleep Awake Review – A One Hit Wonder
Gaming News
Internet Computer (ICP) crashes to $3.50 as AI hype fades and market pressure mounts
Crypto
Crypto Enters First Net-Positive Liquidity Since 2022, Says Delphi Digital
Crypto
Mikel Arteta singles out Arsenal's surprise rivals to win the Premier League title
Sports

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Here’s What You Should Know About Launching an AI Startup

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Here’s What You Should Know About Launching an AI Startup
December 5, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?