CVE-2025-2028
Lack of TLS validation
Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.002
11.9th percentile
Discovered by
Not disclosed
Published
Aug 6, 2025
Assigned by checkpoint
Description
Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs
Weakness: CWE-295
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Check Point | Management Log Server | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- checkpoint · Check Point Management Log Server