CVE-2025-2028

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:checkpoint:log_server:r81.10:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:log_server:r81.20:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:log_server:r82:*:*:*:*:*:*:*

History

27 Aug 2025, 14:13

Type Values Removed Values Added
CPE cpe:2.3:a:checkpoint:log_server:r82:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:log_server:r81.20:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:log_server:r81.10:*:*:*:*:*:*:*
First Time Checkpoint log Server
Checkpoint
Summary
  • (es) Falta de validación TLS al descargar un archivo CSV que incluye la asignación de IP a países utilizados SÓLO para mostrar banderas de países en los registros
References () https://support.checkpoint.com/results/sk/sk183349 - () https://support.checkpoint.com/results/sk/sk183349 - Vendor Advisory

06 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 15:15

Updated : 2025-08-27 14:13


NVD link : CVE-2025-2028

Mitre link : CVE-2025-2028

CVE.ORG link : CVE-2025-2028


JSON object : View

Products Affected

checkpoint

  • log_server
CWE
CWE-295

Improper Certificate Validation