
Python-Exploit für CVE-2024-24919, der auf Check Point-Produkte abzielt und unbefugten Dateizugriff über den /clients/MyCRL-Endpunkt mit Einzelziel- und Batch-Scan-Modi ermöglicht.
Dieses Python-Skript ist ein Exploit für CVE-2024-24919, eine Schwachstelle in Check Point Produkten: (CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, Quantum Spark Appliances) Versionen: (R77.20 (EOL), R77.30 (EOL), R80.10 (EOL), R80.20 (EOL), R80.20.x, R80.20SP (EOL), R80.30 (EOL), R80.30SP (EOL), R80.40 (EOL), R81, R81.10, R81.10.x, R81.20), die unbefugten Zugriff auf sensible Dateien auf einem Zielsystem ermöglicht. Sie zielt auf eine Schwachstelle im /clients/MyCRL-Endpunkt ab.

git clone https://github.com/MohamedWagdy7/CVE-2024-24919
ist eine Datei, die eine Anzahl von Zielen enthält, die eine verwundbare Version ausführen. Diese Ziele wurden mit Shodan unter Verwendung des Dorks "Server: Check Point SVN" "X-UA-Compatible: IE=EmulateIE7" 200 country:"IL" ermittelt.
python exploit.py -d <target> [-f <file>] [-proxy <proxy>] [-o <output>]
python exploit.py -l <list> [-f <file>] [-proxy <proxy>] [-o <output>]
python exploit.py -l ./targets.txt -proxy 127.0.0.1:8080 -o CVE-2024-24919.txt