diff --git a/http/cves/2024/CVE-2024-23692 b/http/cves/2024/CVE-2024-23692 index 5b4a4f401b..7c8569bf95 100644 --- a/http/cves/2024/CVE-2024-23692 +++ b/http/cves/2024/CVE-2024-23692 @@ -1,10 +1,19 @@ id: CVE-2024-23692 info: - name: HFS Command Injection RCE + name: Check Point Quantum Gateway - Information Disclosure author: johnk3r - severity: critical - tags: rce,hfs,cve + severity: high + description: | + CVE-2024-24919 is an information disclosure vulnerability that can allow an attacker to access certain information on internet-connected Gateways which have been configured with IPSec VPN, remote access VPN, or mobile access software blade. + reference: + - https://github.com/rapid7/metasploit-framework/pull/19240 + - https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/ + metadata: + verified: true + max-request: 1 + shodan-query: product:"HttpFileServer httpd" + tags: cve,cve2024,hfs,rce requests: - method: GET