Path traversal in Gaia - CVE-2024-24919
Published: May 29, 2024 / Updated: February 25, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The
vulnerability exists due to a insufficient validation of file path in Security Gateways
with IPSec VPN, Remote Access VPN and the Mobile Access software blade. A
remote non-authenticated attacker can send a specially crafted HTTP request and view arbitrary files on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2024-24919
Links to Public Exploits and PoC-codes
- Exploit #11167 - CVE-2024-24919---Exploit-Script () (February 25, 2025)
- Exploit #10757 - Check Point Security Gateway - Information Disclosure (Unauthenticated) (October 25, 2024)
- Exploit #10579 - CVE-2024-24919 (October 11, 2024)
- Exploit #10348 - CVE-2024-24919 (August 9, 2024)
- Exploit #10278 - CVE-2024-24919 (August 2, 2024)
- Exploit #10241 - CVE-2024-24919 (July 26, 2024)
- Exploit #9995 - CVE-2024-24919 (June 14, 2024)
- Exploit #9961 - CVE-2024-24919-PoC (June 7, 2024)
- Exploit #9940 - CVE-2024-24919 (June 7, 2024)
- Exploit #9927 - CVE-2024-24919-Exploit (June 7, 2024)
- Exploit #9922 - CVE-2024-24919 (June 7, 2024)
- Exploit #9874 - CVE-2024-24919 (May 31, 2024)
- Exploit #9871 - CVE-2024-24919 (May 31, 2024)
- Exploit #9870 - CVE-2024-24919-Check-Point-Remote-Access-VPN (May 31, 2024)
- Exploit #9868 - CVE-2024-24919 (May 31, 2024)
- Exploit #9867 - CVE-2024-24919 (May 31, 2024)
- Exploit #9866 - CVE-2024-24919 (May 31, 2024)