CVE-2024-24919
Information disclosure
- Published
- May 28, 2024
- Updated
- Aug 5, 2026
- Assigning CNA
- checkpoint
- Evidence observed
- May 30, 2024
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
Sources
53Proof-of-concept exploit for CVE-2024-24919, an unauthenticated file read in Check Point Security Gateways; scans single or multiple IP targets and logs results.
- CVE-2024-24919Scanner
Scans web applications for CVE-2024-24919 vulnerabilities via CLI, supporting a single target or wordlist-based bulk URL scanning.
- CVE-2024-24919Exploit
Exploit script for Check Point CVE-2024-24919 that reads arbitrary sensitive files via the vulnerable /clients/MyCRL endpoint, supporting single and batch targets with proxy and output options.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.