
SOC287 - Arbitrary File Read on Checkpoint Security Gateway [CVE-2024-24919]
This repository contains a detailed walkthrough of the CVE-2024-24919 vulnerability affecting Check Point Security Gateways. The vulnerability allows arbitrary file read, potentially exposing sensitive system files such as /etc/passwd. This write-up provides an in-depth analysis of the attack scenario, detection methods, and mitigation strategies.
For a detailed walkthrough of this Let's Defend SOC lab, please refer to: SOC287 Lab Walkthrough
In this incident, an attacker exploited CVE-2024-24919 to send a directory traversal payload via an HTTP POST request to access the /etc/passwd file on the target. Below are the key details from the alert: