CVE-2025-2028

Lack of TLS validation

Severity
Medium 6.5
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
0.002
10.6th percentile
Discovered by
Not disclosed
Published
Aug 6, 2025
Assigned by checkpoint

Description

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Check Point Management Log Server Network & Security Management cna-assigner
Vendor-reported products (1)
  • checkpoint · Check Point Management Log Server

Something wrong here?