Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2024-24919 PoC — Information disclosure

Source
Associated Vulnerability
Title:Information disclosure (CVE-2024-24919)
Description:Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
Readme
# CVE-2024-24919-Check-Point-Remote-Access-VPN

**CVE-2024-24919** is an unauthenticated arbitrary file read vulnerability that can be treated nothing less than a full unauthenticated RCE. An attacker can read any sensitive files located on the affected appliance with **superuser** access. An attacker can retrieve the contents of the ntds.dit or /etc/password file and can use them login to systems, and if the Security Gateway allows password only authentication, the attacker may use the cracked passwords to authenticate.

**Affected product and versions**: CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, Quantum Spark Appliances
                               R77.20 (EOL), R77.30 (EOL), R80.10 (EOL), R80.20 (EOL), R80.20.x, R80.20SP (EOL), R80.30 (EOL), R80.30SP (EOL), R80.40 (EOL), R81, R81.10, R81.10.x, R81.20

**Usage**: python3 scanner.py -i <Target_IP>

**Usage**: python3 exploit.py -i <Target_IP>

**Disclaimer**: This exploit is to be used only for educational and authorized testing purposes. Illegal/unauthorized use of this exploit is prohibited. I am not responsible for any misuse or damage caused by this script.

**References**:
https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/
https://www.rapid7.com/blog/post/2024/05/30/etr-cve-2024-24919-check-point-security-gateway-information-disclosure/
File Snapshot

[4.0K] /data/pocs/aa591c813f5900e669031e2d3ca6fe41c2714309 ├── [4.8K] exploit.py ├── [1.4K] README.md └── [1.4K] scanner.py 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →