Article Details

Scrape Timestamp (UTC): 2024-05-29 15:29:41.710

Source: https://thehackernews.com/2024/05/check-point-warns-of-zero-day-attacks.html

Original Article Text

Click to Toggle View

Check Point Warns of Zero-Day Attacks on its VPN Gateway Products. Check Point is warning of a zero-day vulnerability in its Network Security gateway products that threat actors have exploited in the wild. Tracked as CVE-2024-24919, the issue impacts CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark appliances. "The vulnerability potentially allows an attacker to read certain information on Internet-connected Gateways with remote access VPN or mobile access enabled," Check Point said. Hotfixes are available in the following versions - The development comes days after the Israeli cybersecurity company warned of attacks targeting its VPN devices to infiltrate enterprise networks. "By May 24, 2024, we identified a small number of login attempts using old VPN local-accounts relying on unrecommended password-only authentication method," it noted earlier this week. This has now been traced back to a new high-severity zero-day discovered in Security Gateways with IPSec VPN, Remote Access VPN and the Mobile Access software blade. Check Point did not elaborate on the nature of the attacks, but noted in an FAQ that the exploitation attempts observed so far focus on "remote access on old local accounts with unrecommended password-only authentication" against a "small number of customers." The targeting of VPN devices represents just the latest series of attacks to target network perimeter applications, with similar attacks impacting devices from Barracuda Networks, Cisco, Fortinet, Ivanti, Palo Alto Networks, and VMware in recent years. "Attackers are motivated to gain access to organizations over remote-access setups so they can try to discover relevant enterprise assets and users, seeking for vulnerabilities in order to gain persistence on key enterprise assets," Check Point said.

Daily Brief Summary

CYBERCRIME // Check Point Discovers Zero-Day Vulnerability in VPN Gateways

Check Point has issued a warning regarding a zero-day vulnerability found in several of its Network Security gateway products.

The identified vulnerability, tracked as CVE-2024-24919, affects CloudGuard Network, Quantum Maestro, and other related appliances, making them susceptible to unauthorized data access.

Threat actors have exploited this vulnerability to target enterprise networks through VPN devices, primarily focusing on remote access exploitation.

Check Point has traced recent security breaches back to exploitation attempts against outdated and insecure VPN accounts.

Hotfixes for this high-severity vulnerability have been released for affected models to mitigate potential threats.

This incident follows a broader trend of attacks aimed at network perimeter devices similar to those experienced by other major cybersecurity firms like Cisco and Fortinet.

Check Point emphasized that attackers are leveraging such vulnerabilities to gain persistent access to enterprise networks and advised urgent updates to secure remote access points.