# Check Point Security Gateway information disclosure of password hashes

Source: https://startwithidentity.com/cves/cve-2024-24919/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Check Point Security Gateways (including VPN and firewall blades) exposed files that contained password hashes to an unauthenticated caller. Those hashes include local admin and, in some configurations, VPN user material. CISA added CVE-2024-24919 to KEV. Check Point shipped a hotfix in late May 2024. Exploitation followed.

## Why it matters

A VPN gateway is an [identity provider](https://startwithidentity.com/glossary/identity-provider/) for remote access. Leaking its hashes is credential theft at the enforcement point, after which MFA on the same box may not save you if the attacker cracks a local account or replays a legacy hash. Same product class as Ivanti Connect Secure and FortiCloud SSO.

## What to do

- Apply the Check Point hotfix. If the gateway was internet-facing in May 2024, rotate local admin and VPN credentials and review logs for unexpected reads of the leaked paths.
- Move VPN users onto [phishing-resistant MFA](https://startwithidentity.com/glossary/phishing-resistant-mfa/) that does not share a hash file with the appliance OS.
- Do not leave the management or information-leak paths on the same interface as the VPN.

## After you patch

Edge appliances sit outside the estate and hold credentials into it, which is why this class keeps producing multi-victim campaigns.

- **Revoke all sessions on the appliance**, then rotate the directory or [LDAP](https://startwithidentity.com/glossary/federation/) service account it uses for authentication.
- **Rotate certificates and any stored integration credentials**, since configuration stores on these devices are a routine post-exploitation target.
- **Hunt for authenticated sessions with no matching interactive login**, and for logins from ASNs that had never appeared before the disclosure date.
- **Check downstream**: anything the appliance could reach or authenticate to is in scope, including [SSO](https://startwithidentity.com/glossary/sso/)-connected applications.

## Sources

- [NVD: CVE-2024-24919](https://nvd.nist.gov/vuln/detail/CVE-2024-24919)
- CISA KEV
- Check Point sk182337 / May 2024 hotfix
