City
Epaper

Indian cyber security agency warns users about a bug in Checkpoint gateway products

By IANS | Updated: June 1, 2024 18:05 IST

New Delhi, June 1 The Indian Computer Emergency Response Team (CERT-In) has warned about a vulnerability in Checkpoint ...

Open in App

New Delhi, June 1 The Indian Computer Emergency Response Team (CERT-In) has warned about a vulnerability in Checkpoint Network Security gateway products, which could allow hackers to compromise users’ data.

According to its advisory by the national cyber-security agency, attackers can use the vulnerability to access certain information on “internet-connected gateways configured with IPSec VPN, remote access VPN, or mobile access software blades”.

This, in certain scenarios, could potentially lead the attacker to move laterally and gain domain admin privileges, warned the agency.

The vulnerability exists in Checkpoint Network Security gateway products due to the unrecommended password-only authentication method.

“The vulnerability (CVE-2024-24919) is being exploited in the wild,” said CERT-In, urging users to apply fixes issued by the company.

Checkpoint has discovered the vulnerability and issued the fix.

“Following our security update, Check Point's dedicated task force continues investigating attempts to gain unauthorised access to VPN products used by our customers,” said the company in its security update.

“Exploiting this vulnerability can result in accessing sensitive information on the Security Gateway,” it added.

CERT-In, which comes under the Ministry of Electronics & Information Technology, last week warned users of vulnerabilities in Google Chrome and Siemens products, which could allow an attacker to execute arbitrary code on the targeted system.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

International"Iran declared victory by waging asymmetric war in response": former US Treasury counterterrorism analyst

BusinessUS court accepts plea filed by Adani's counsel seeking pre-motion conference to dismiss SEC case

BusinessRBI lowers GDP growth for FY 27 to 6.9%; Inflation hiked to 4.6% due to West Asia crisis, spike in crude prices

BusinessColgate Makes Preventive Dental Care Accessible to All with FREE Dental Check-Ups

NationalForest guard killed as sand mafia attacks raiding team in MP's Morena

Technology Realted Stories

TechnologyRBI raises India’s real GDP growth to 7.6 pc for FY26, pegs FY27 at 6.9 pc

TechnologyRBI holds repo rate at 5.25 pc, maintains neutral instance amid global uncertainty

TechnologyCrude oil prices tank up to 20 pc over Iran ceasefire announcement

TechnologyLegally flawed, outside US jurisdiction: Adani tells judge to dismiss SEC fraud suit

TechnologyIndian stock market surges over 3 pc over Iran ceasefire, Sensex jumps 2,775 points