> Source: [sk182357](https://support.checkpoint.com/results/sk/sk182357)

# sk182357 - Preventative Hotfix for CVE-2024-24919 - Spark Firewall

| Property | Value |
|----------|-------|
| Solution ID | sk182357 |
| Date Created | 2024-06-01 |
| Last Modified | 2025-02-23 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |

## Solution

**For Security Gateways that run the Gaia OS, refer to [sk182336: Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure](https://support.checkpoint.com/results/sk/sk182336).**

Following our security update on May 27, 2024, Check Point's dedicated task force continues investigating attempts to gain unauthorized access to VPN products used by our customers. On May 28, 2024 we discovered a vulnerability (CVE-2024-24919) in Security Gateways with Remote Access VPN or the Mobile Access software blade enabled. Exploiting this vulnerability can result in accessing sensitive information on the Security Gateway.  
This, in certain scenarios, can potentially lead the attacker to move laterally and gain domain admin privileges.  
If you need any additional assistance, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) or your local Check Point representative.

### Quantum Spark Gateway images that include the mandatory Hotfix to prevent exploit of CVE-2024-24919 {#Fix}

> |----------------------------|------------------------|------------------------------------------------------------------------------|
> | Firmware Version           | Minimum Required Build | SK Article                                                                   |
> | **R81.10.15 (and higher)** | Build 996003913        | See [sk182438](https://support.checkpoint.com/results/sk/sk182438)           |
> | **R81.10.10**              | Build 996002945        | See [sk181080](https://support.checkpoint.com/results/sk/sk181080#Downloads) |
> | **R81.10.08**              | Build 996001750        | See [sk181079](https://support.checkpoint.com/results/sk/sk181079#Downloads) |
> | **R80.20.60**              | Build 992002903        | See [sk179922](https://support.checkpoint.com/results/sk/sk179922#Downloads) |
> | **R77.20.87**              | Build 990173160        | See [sk151574](https://support.checkpoint.com/results/sk/sk151574#Downloads) |
> | **R77.20.81**              | Build 990172628        | See [sk137212](https://support.checkpoint.com/results/sk/sk137212#Downloads) |

<br />

### Step 1 of 3 - Check the current firmware build on your Quantum Spark Gateway

1. Connect to the WebUI on the Quantum Spark Gateway from a computer on an internal network:

   `https://<IP Address of Appliance>:4434`

   Example: *https://192.168.1.1:4434*
2. On the left panel, click the **Home** view.

3. In the **Overview** section, click the **System** page.

4. Below the hostname, refer to the field **Version**.

   Example:

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/Version202406131030241.png)

<br />

### Step 2 of 3 - Upgrade your Quantum Spark Gateway to an image that includes the mandatory Hotfix to prevent exploit of CVE-2024-24919

> **Note** - If your Quantum Spark Gateway already runs one of the mandatory firmware images, then it is **not** necessary to upgrade again, unless you received a private firmware build from Check Point Support (the private firmware build must be greater than the mandatory build listed above).
>
> 1. Download the mandatory firmware image from the corresponding Home Page SK article (see the summary table above).
>
> 2. Follow the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Backup-Restore-Upgrade-and-Other-System-Operatons.htm) \> chapter "Managing the Device" \> section "Backup, Restore, Upgrade, and Other System Operations".

<br />

### Step 3 of 3 - Follow the important extra measures

> Click each item to see the content or click here to see the Entire Section
>
> 1. Disable the Remote Access VPN blade  
> > If you do not use the **Remote Access VPN** feature, then disable it:
> >
> > 1. Click the **VPN** view.
> >
> > 2. In the **Remote Access** section, click **Blade Control**.
> >
> > 3. At the top of the page, click **Off**.
> >
> > ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image001202406011653001.png)
> >
> > See the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Notifications.htm) \> chapter "Managing VPN" \> section "Configuring the Remote Access Blade".
>
> 2. Change the passwords for administrator users (and use complex passwords) and local users  
> > See the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Notifications.htm) \> chapter "Managing Users and Objects" \> section "Configuring Local and Remote System Administrators".
> >
> > 1. Enforce the password complexity for Administrator users:
> >
> >    1. Click the **Users \& Objects** view.
> >
> >    2. In the **Users Management** section, click **Administrators**.
> >
> >    3. From the toolbar, click **Security Settings**.
> >
> >       ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image003202406011653302.png)
> >    4. Select **Enforce password complexity for administrators**.
> >
> >       ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image005202406011654013.png)
> > 2. Change the password for each Administrator user:
> >
> >    1. Select each Administrator \> from the toolbar, click **Edit**.
> >    2. Enter a new password.
> >
> >    3. Click **Save**.
> >
> >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image006202406011733261.png)
> > 3. Change the password for each Local User:
> >
> >    1. Click the **Users \& Objects** view.
> >
> >    2. In the **Users Management** section, click **Users**.
> >
> >    3. Select each Local User \> from the toolbar, click **Edit**.
> >
> >    4. Enter a new password.
> >
> >    5. Click **Save**.
> >
> > 4. Change the password for each Remote Access VPN User:
> >
> >    1. Click the **VPN** view.
> >
> >    2. In the **Remote Access** section, click **Remote Access Users**.
> >
> >    3. Select each Remote Access VPN User \> from the toolbar, click **Edit**.
> >
> >    4. Enter a new password.
> >
> >    5. Click **Save**.
>
> <br />
>
> 3. Restrict access through "Reach My Device"  
> > We do **not** recommend to allow access to your appliance through "Reach My Device" from the Internet.
> >
> > If such access is necessary, then restrict the access to specific IP addresses only:
> >
> > See the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Notifications.htm) \> chapter "Managing the Device" \> section "Configuring DDNS and Access Service" \> section "Reach My Device".
> >
> > 1. Click the **Device** view.
> >
> > 2. In the **System** section, click **Administrator Access**.
> >
> > 3. In the section **Access from the above sources is allowed from** , select **Specified IP addresses from the Internet and any IP address from other sources**.
> >
> > 4. Click **New** \> configure the applicable IP address \> click **Save**.
> >
> > 5. In the bottom right corner, click **Save**.
> >
> > ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image007202406011654214.png)
>
> 4. Enable Two-Factor Authentication for Administrators (R81.10.10 and higher)  
> > Two-Factor Authentication is an extra layer of security on the Quantum Spark Gateway. When Two-Factor Authentication is enabled on the **Administrator Access** page, its use is mandatory for all administrators configured on the appliance and is required for login.
> >
> > **Important** - Before you enable the 2FA, read all the information in the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-Administrator-Access.htm) \> chapter "Managing the Device" \> section "Configuring Administrator Access" \> section "Two-Factor Authentication (2FA)".
> >
> > 1. Click the **Device** view.
> >
> > 2. **Recommended:** Configure the Quantum Spark Gateway to use a Network Time Protocol (NTP) server to set the date and time. This helps avoid sync issues with the Authenticator app on users' mobile devices.
> >
> >    1. In the **System** section, click **Date and Time**.
> >    2. In the section **Adjust Date and Time** , select **Set date and time using a Network Time Protocol (NTP) server**.
> >    3. Configure the applicable NTP settings.
> >    4. In the bottom right corner, click **Save**.
> > 3. In the **System** section, click **Administrators**.
> >
> > 4. Edit each administrator to make sure it has both an email address and a phone number configured.
> >
> > 5. In the **System** section, click **Administrator Access**.
> >
> > 6. In the **Two-Factor Authentication (2FA)** section, select **Enable Two-Factor Authentication enforcement**.
> >
> >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image009202406011654375.png)
> > 7. In the bottom right corner, click **Save**.
> > 8. The Quantum Spark Gateway sends an email (from `do-not-reply@portal.checkpoint.com`) to all configured administrators that explains how to use the Authenticator app.
> >
> > 9. In the Web UI popup window, select **I received email** if you received the email or click **Resend email**.
> >
> > 10. Each administrator must install the Authenticator app on their mobile devices.
> >
> > 11. In the Authenticator app, each administrator must add a new account.
> >
> > 12. During the login, select the method to receive an authentication code.
> >
> >     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image011202406011654586.png)
>
> 5. Enable Two-Factor Authentication for Remote Access VPN users (R81.10.10 and higher)  
> > Two-Factor Authentication is an extra layer of security on the Quantum Spark Gateway. When Two-Factor Authentication is enabled for Remote Access VPN, its use is mandatory for all such users configured on the appliance.
> >
> > **Important** - Before you enable the 2FA, read all the information in the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-Remote-Access-Blade.htm) \> chapter "Managing VPN" \> section "Configuring the Remote Access Blade".
> >
> > **Prerequisite:** To use Two-Factor Authentication for Remote Access VPN, a user you must have these settings:
> >
> > 1. Click the **VPN** view.
> >
> > 2. In the **Remote Access** section, click **Remote Access Users**.
> >
> >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image019202406011656149.png)
> > 3. Edit each applicable user object \> configure an email address, a mobile phone number, and select **Remote Access permissions**.
> >
> >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image0212024060116562810.png)
> > 4. Click **Apply**.
> >
> > **Procedure:**
> >
> > 1. Click the **VPN** view.
> >
> > 2. In the **Remote Access** section, select **Require users to confirm their identity using Two-Factor Authentication**.
> >
> >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image013202406011804541.png)
> > 3. On the right end of this line, click **Configure**.
> >
> >    The **Two-Factor Authentication Settings** window opens.
> > 4. On the **Configuration** tab, select and configure the applicable options.
> >
> >    To select to receive by both SMS and email, select both checkboxes.
> >
> >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image015202406011655297.png)
> > 5. On the **Advanced** tab, configure the applicable options.
> >
> >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image017202406011655438.png)
> > 6. Click **Save** to close the **Two-Factor Authentication Settings** window.
> >
> > 7. In the bottom right corner, click **Save**.
>
> 6. Enable notifications for administrator access  
> > See the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Notifications.htm) \> chapter "The Home Tab" \> section "Notifications".
> >
> > 1. Click the **Home** view.
> >
> > 2. In the **Monitoring** section, click **Notifications**.
> >
> > 3. From the toolbar, click **Settings**.
> >
> > 4. Select and configure these:
> >
> >    1. **An administrator is logged in**
> >
> >    2. **An administrator is logged in to the Expert Shell**
> >
> >    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image0232024060116564711.png)
> > 5. Click **Save**.
>
> <br />
>
> 7. Reinitialize Internal Certificate Authority (CA)  
> > **Important** - This action creates new certificates for the Internal CA, VPN, and SSL Inspection. This also resets the cluster configuration - you must configure the cluster again.
> >
> > 1. Click the **Device** view.
> >
> > 2. In the **Certificates** section, click **Internal Certificate**.
> >
> > 3. Click **Reinitialize Certificates**.
> >
> > 4. In the **Host/IP address** field, enter the applicable IP address.
> >
> >    Normally, the device suggests its own host name (when DDNS is configured) or its external IP address.
> >
> >    If you have multiple Internet connections configured, in load sharing mode, you can manually enter an accessible IP address for this appliance.
> >
> >    This is used by remote sites to access the internal CA and check for certificate revocation.
> > 5. In the **Internal VPN Certificate will be valid for** field, select the applicable number of years for which the Internal VPN Certificate is valid.
> >
> >    The default is 3.
> >
> >    The maximum value allowed is 20.
> > 6. Click **Apply**.
> >
> > Note - The internal VPN certificate expiration date cannot be later than the CA expiration date.
> >
> > ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image030202406030714141.png)
> >
> > See the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Managing-Internal-Certificates.htm) \> chapter "Managing the Device" \> section "Managing Internal Certificates".
>
> 8. Change the shared secret in the RADIUS Server settings  
> > 1. On the RADIUS Server, change the shared secret (refer to the documentation of the RADIUS Server vendor).
> >
> > 2. Click the **Users \& Objects** view.
> >
> > 3. In the **Users Management** section, click **Authentication Servers**.
> >
> > 4. In the **RADIUS Servers** section, click each configured server.
> >
> > 5. In the **Shared secret** field, enter a new secret.
> >
> > 6. Click **Apply**.
> >
> > ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image031202406030746111.png)
> >
> > See the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Managing-Authentication-Servers.htm) \> chapter "Managing Users and Objects" \> section "Managing Authentication Servers".
>
> 9. Change the shared secret in the TACACS+ Server settings  
> > 1. On the TACACS+ Server, change the shared secret (refer to the documentation of the TACACS+ Server vendor).
> >
> > 2. Click the **Users \& Objects** view.
> >
> > 3. In the **Users Management** section, click **Authentication Servers**.
> >
> > 4. In the **TACACS+ Servers** section, click each configured server.
> >
> > 5. In the **Shared secret** field, enter a new secret.
> >
> > 6. Click **Apply**.
> >
> > ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image032202406030746282.png)
> >
> > See the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Managing-Authentication-Servers.htm) \> chapter "Managing Users and Objects" \> section "Managing Authentication Servers".
>
> 10. Change the password in the Active Directory server settings  
> > 1. On the Active Directory server, change the shared secret (refer to the documentation of the Active Directory server vendor).
> >
> > 2. Click the **Users \& Objects** view.
> >
> > 3. In the **Users Management** section, click **Authentication Servers**.
> >
> > 4. In the **Active Directory** section, click each configured server and click **Edit**.
> >
> > 5. In the **Password** field, enter a new password.
> >
> > 6. Click **Apply**.
> >
> > ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image033202406030746423.png)
> >
> > See the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Managing-Authentication-Servers.htm) \> chapter "Managing Users and Objects" \> section "Managing Authentication Servers".
>
> 11. Change the password in the Wireless settings  
> > 1. Click the **Device** view.
> >
> > 2. In the **Network** section, click **Wireless**.
> >
> > 3. In the **2.4GHz** section, click **Edit Settings**.
> >
> > 4. At the top, click the **Configuration** tab.
> >
> > 5. In the **Wireless Security** section, if you selected **Protected network (recommended)** , then in the **Network** password field, enter a new password.
> >
> > 6. Click **Apply**.
> >
> > 7. Repeat the same steps in the **5GHz** section.
> >
> > ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182357/image034202406030715115.png)
> >
> > See the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-Wireless-Network.htm) \> chapter "Managing the Device" \> section "Configuring the Wireless Network".

<br />

### Article Revision History {#RevisionHistory}

Show / Hide revision history  

|--------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Date         | Description                                                                                                                                                                                                                                                                                                                                                        |
| 15 July 2024 | Corrected the sentence from "On May 28, 2024 we discovered a vulnerability in Security Gateways with IPsec VPN in Remote Access VPN community and the Mobile Access software blade (CVE-2024-24919)." to "On May 28, 2024 we discovered a vulnerability (CVE-2024-24919) in Security Gateways with Remote Access VPN or the Mobile Access software blade enabled." |
| 07 July 2024 | In Step 2 "Follow the important extra measures", updated the sub-step #2 from "Change the Administrator passwords and use complex passwords" to "Change the passwords for administrator users (and use complex passwords) and local users"                                                                                                                         |
| 13 June 2024 | Added the steps to check the current firmware build Improved the text in the existing steps                                                                                                                                                                                                                                                                        |
| 06 June 2024 | In Step 1 "Upgrade your Quantum Spark Gateway", removed irrelevant information about the Minimum Required Build                                                                                                                                                                                                                                                    |
| 03 June 2024 | In Step 2 "Follow the important extra measures", added new steps: * Reinitialize Internal Certificate Authority (CA) * Change the shared secret in the RADIUS Server settings * Change the shared secret in the TACACS+ Server settings * Change the password in the Active Directory server settings * Change the password in the Wireless settings               |
| 01 June 2024 | First release of this article                                                                                                                                                                                                                                                                                                                                      |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
