Critical authentication bypass vulnerability exploited by ransomware groups since early May now has emergency fix.
Summary
- Check Point patched critical VPN authentication bypass bug CVE-2024-50751 after month of active exploitation
- Attacks began May 7, with Qilin ransomware affiliate among threat actors exploiting the flaw
- Vulnerability affects Remote Access VPN and Mobile Access deployments using deprecated IKEv1 protocol
- Several dozen organisations globally confirmed compromised, with CISA adding to Known Exploited Vulnerabilities catalogue
The Vulnerability
Check Point released emergency patches on Monday for CVE-2024-50751, a critical authentication bypass vulnerability in Remote Access VPN and Mobile Access products. The flaw stems from a logic-flow weakness in certificate validation that allows remote attackers to establish VPN connections without user passwords. The vulnerability affects Mobile Access/SSL VPNs, Remote Access VPNs, and Spark Firewalls configured with the deprecated IKEv1 key exchange protocol.
Active Exploitation Timeline
Threat actors began exploiting the vulnerability on May 7, according to Check Point VP of research Lotem Finkelstein. Attack activity intensified in early June before Check Point detected suspicious activity and began investigating on June 4. The security vendor confirmed exploitation remained limited to several dozen organisations globally, primarily in recent days leading up to the patch release.
Ransomware Connection
In at least one confirmed case, investigators observed post-compromise activity linked to a Qilin ransomware affiliate. Check Point notes this same threat actor group is likely exploiting similar VPN vulnerabilities in Palo Alto Networks, Fortinet, and F5 products, suggesting a coordinated campaign targeting VPN infrastructure across multiple vendors.
Additional Discovery
While investigating CVE-2024-50751, Check Point identified a second vulnerability, CVE-2024-50752, affecting Security Gateways and Spark Firewall products. This additional flaw involves certificate validation logic bugs in the deprecated IKEv1 protocol that could enable man-in-the-middle attacks on site-to-site VPN configurations. Check Point reports no confirmed exploitation of this second vulnerability.
CISA Response
The Cybersecurity and Infrastructure Security Agency has added CVE-2024-50751 to its Known Exploited Vulnerabilities catalogue, reflecting the active threat landscape. This designation typically triggers mandatory patching requirements for federal agencies and serves as a strong signal to private sector organisations about exploitation risk.
Why it matters
This incident demonstrates the critical window of exposure when zero-day vulnerabilities are actively exploited before vendors detect and patch them. For CISOs, it highlights the ongoing targeting of VPN infrastructure by ransomware groups and the particular risk associated with legacy protocols like IKEv1. The month-long exploitation window before detection underscores the importance of comprehensive monitoring and the challenge of identifying sophisticated authentication bypass attacks.
What to do now
- Apply Check Point hotfixes immediately for vulnerable gateways and firewalls
- Review Check Point SmartConsole logs for VPN certificate authentication attempts from May 7 through June 5
- Search logs for indicators of compromise including attacker IP addresses and certificate subject names provided by Check Point
- Implement alternative mitigation options if immediate patching isn’t possible, following Check Point security advisory instructions
- Consider migrating away from deprecated IKEv1 protocol configurations where feasible
