Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
By June 4, 2024, GreyNoise had recorded more than 10,000 attempts to exploit Check Point vulnerability CVE-2024-24919, coming from 781 unique IP addresses. The flaw could let attackers read files on affected internet-connected Security Gateways. Exploitation was reported before Check Point’s public advisory, then rose sharply after technical details and proof-of-concept code appeared.
What was the Check Point VPN zero-day?
CVE-2024-24919 was a path-traversal vulnerability in Check Point Security Gateways with Remote Access VPN in IPsec VPN communities or the Mobile Access software blade enabled. Check Point said the flaw potentially allowed an attacker to read certain information on internet-connected gateways with those features enabled.
Because the vulnerability could permit arbitrary file reads, requested files might contain usernames, passwords, or other sensitive gateway information. A file request observed in traffic does not, on its own, prove that the attacker successfully read the file or intended to steal credentials; it may also have been a test of the vulnerability.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →How many attempts were recorded, and when did activity increase?
GreyNoise reported more than 10,000 exploitation attempts from 781 unique IP addresses by June 4, 2024. Those figures describe observed attempts and source IPs, not confirmed compromises, successful file reads, or a count of individual attackers.
#1 Best Overall
- Product Type:Network Security/Firewall Appliance
- Product Series:N
- Brand Name:Check Point
- Manufacturer:Check Point Software Technologies, Ltd
- Product Model:CPUTM-EDGE-N8
| Date | Reported activity |
|---|---|
| At least April 7, 2024 | SecurityWeek reported that exploitation in the wild had begun by this date. |
| May 27–28, 2024 | Check Point issued customer alerts and published its security update and mitigation guidance. |
| May 30, 2024 | GreyNoise observed initial attempts, which used non-working payloads. |
| May 31, 2024 | Working exploitation appeared after watchTowr published technical details and proof-of-concept code. |
| June 2–4, 2024 | GreyNoise observed a sharp increase; by June 4 it had logged the attempt and IP totals above. |
The timing makes two points important for incident response: exploitation was reported before the public disclosure, and the public release of working technical details was followed by a rapid rise in attempts. GreyNoise’s first observed attempts on May 30 are not the same as the reported start of in-the-wild exploitation.
Which gateways were at risk?
The affected configuration was a Check Point Security Gateway with Remote Access VPN or Mobile Access enabled. The advisory’s scope is configuration-based; the available reporting does not establish that every Check Point gateway was vulnerable regardless of enabled features.
Rank #2
- Product Description: Check Point Quantum Spark 1500 PRO - security appliance - 1555 - with 3 year SandBlast (SNBT) Security Subscription Package and Direct Premium support
- Device Type: Security appliance
- Bundled Services: 3 year SandBlast (SNBT) Security Subscription Package and Direct Premium support
- Form Factor: Desktop
- Data Link Protocol: Ethernet, Fast Ethernet, Gigabit Ethernet
What should administrators do?
- Install Check Point’s supplied fix or preventive solution. The vendor’s May 28, 2024 advisory described the supplied fix as mandatory for protection. Use Check Point’s applicable security update and mitigation guidance for the gateway rather than assuming that account changes alone remediate the vulnerability.
- Review local accounts. Determine which local accounts are needed, whether they were used, and by whom. Disable accounts that are not required.
- Strengthen authentication for retained accounts. Where local accounts must remain, add another factor such as certificates instead of relying on password-only authentication. Check Point specifically warned that observed attempts focused on older local accounts protected only by passwords.
- Investigate possible exposure. Review gateway logs and assess whether credentials or other sensitive information could have been exposed through file reads. The available sources describe the risk but do not provide a universal forensic checklist, so investigation should be adapted to the gateway and the organization’s logging and incident-response procedures.
There is a practical trade-off in the order of work: applying the vendor’s protection addresses the vulnerability, while preserving and reviewing relevant evidence can help establish whether the gateway was targeted or data exposed. The reports establish that exploitation preceded disclosure, but do not specify a single evidence-preservation procedure suitable for every environment.
Who was behind the activity?
The available reporting does not verify a named threat actor. The scale and spread of observed attempts support describing a rapid, multi-source exploitation wave, not attributing it to a particular group or individual.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

