Security Management and SmartConsole
CVE-2024-24911: Out of Bounds read in the CPCA process on Check Point Management Server
In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Multi-Domain Security Management, Quantum Security Management Quantum Security Management R81 (EOS), R81.10, R81 | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL cache.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.