> Source: [sk185175](https://support.checkpoint.com/results/sk/sk185175)

# sk185175 - IPS log shows CVE-2024-24919 traffic from a Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk185175 |
| Date Created | 2026-08-05 |
| Last Modified | 2026-08-10 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * A Security Gateway with IPS Software Blade enabled generates a Prevent log for this protection:   

  * **Protection:** Check Point VPN Information Disclosure (CVE-2024-24919)
  * **Protection IDv** asm_dynamic_prop_CVE_2024_24919
  * **Attack name:** SSL Protection Violation
  * **Service:** TCP/18264 (FW1_ica_services)
  * **Resource:** `http://<Management_Server_IP>:18264/clients/MyCRL`

  <br />

  The environment contains  
  * An external Security Gateway with Check Point Proxy for ICA Services (CPAS) enabled and IPS disabled.
  * An internal Security Gateway with IPS enabled.
  * A Security Management Server located behind the internal Security Gateway.

  <br />

* The IPS log shows:   

  * **Severity:** High
  * **Confidence:** High
  * **Source:** The external Security Gateway
  * **Destination:** The internal Security Management Server

  <br />

## Cause

This behavior can be expected when Check Point Proxy for ICA Services (CPAS) is enabled.  
CPAS proxies ICA-related connections between external clients and the Security Management Server. When an external client connects to TCP port 18264 on a Security Gateway, the Security Gateway creates a corresponding connection to the Security Management Server.   
To prevent direct exposure of the Security Management Server address, the external Security Gateway uses its own IP address as the source of the proxied connection.  
As a result, an intermediate Security Gateway that performs IPS inspection sees the connection as originating from the external Security Gateway instead of the original external client.  
TCP port 18264 carries ICA-related traffic, including Certificate Revocation List (CRL) retrieval requests. IPS inspection of this traffic can trigger the Check Point VPN Information Disclosure (CVE-2024-24919) protection even when the traffic is legitimate CPAS traffic.  

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
