The ACSC has reported a vulnerability in devices from Check Points’ Quantum Security Gateway and acknowledges active exploitation of these susceptible systems.
Check Point has released a preventive hotfix for CVE-2024-24919 and mentioned that its team is currently investigating unauthorized access attempts on VPN products used by clients.
According to the advisory from Check Point released on May 28, 2024, a security flaw was identified in Security Gateways employing IPsec VPN in the Remote Access VPN community along with the Mobile Access software blade (CVE-2024-24919). The successful exploitation of this vulnerability can lead to unauthorized access to critical information stored on the Security Gateway, potentially allowing the attacker to escalate privileges and move laterally within the network.
The ACSC advises Australian organizations to conduct a network assessment to identify any vulnerable instances and apply the recommended mitigation measures. The agency strongly urges affected organizations in Australia to prioritize patching this vulnerability promptly.
