#VU89894 Path traversal in Gaia - CVE-2024-24919
Published: May 29, 2024 / Updated: February 25, 2025
Gaia
Check Point Software Technologies
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The
vulnerability exists due to a insufficient validation of file path in Security Gateways
with IPSec VPN, Remote Access VPN and the Mobile Access software blade. A
remote non-authenticated attacker can send a specially crafted HTTP request and view arbitrary files on the system.
Note, the vulnerability is being actively exploited in the wild.