« Back to list

CVE-2024-24911

Status: AnalyzedHigh (7.5)—

In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL cache.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-24911",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-24911",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-06T14:11:40.331277Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@checkpoint.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@checkpoint.com",
      "affectedData": [
        {
          "vendor": "checkpoint",
          "product": "Multi-Domain Security Management, Quantum Security Management",
          "versions": [
            {
              "status": "affected",
              "version": "Quantum Security Management R81 (EOS), R81.10, R81.20"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-02-06T14:15:29.577",
  "references": [
    {
      "url": "https://support.checkpoint.com/results/sk/sk183101",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@checkpoint.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@checkpoint.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL cache."
    },
    {
      "lang": "es",
      "value": "En casos excepcionales, el proceso cpca en el servidor de administración de seguridad o servidor de administración de dominio puede cerrarse inesperadamente y crear un archivo de volcado de memoria. Cuando el proceso cpca deja de funcionar, pueden surgir problemas de conectividad de VPN y SIC si la CRL no está presente en la caché de CRL de Security Gateway."
    }
  ],
  "lastModified": "2026-06-17T07:15:12.770",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:checkpoint:gaia_os:r81:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C580EA73-A731-497E-885E-F00854E07EA9"
            },
            {
              "criteria": "cpe:2.3:o:checkpoint:gaia_os:r81.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55864700-51C8-4540-B4B2-05CE4C7FC245"
            },
            {
              "criteria": "cpe:2.3:o:checkpoint:gaia_os:r81.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BE80E1E-02E1-44E3-B309-3079F0F5A89C"
            },
            {
              "criteria": "cpe:2.3:o:checkpoint:gaia_os:r82:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6443AE50-1CB5-4D00-8C8D-97DB966687DD"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:checkpoint:multi-domain_management:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1584E1B4-412C-40E2-BF07-4E464692F2AE"
            },
            {
              "criteria": "cpe:2.3:h:checkpoint:quantum_security_management:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "08601413-25E2-4977-B67A-C11A9D788EA8"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@checkpoint.com"
}