CVE-2025-2028

Lack of TLS validation

Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.002
11.9th percentile
Discovered by
Not disclosed
Published
Aug 6, 2025
Assigned by checkpoint

Description

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Check Point Management Log Server Network & Security Management cna-assigner
Vendor-reported products (1)
  • checkpoint · Check Point Management Log Server

Something wrong here?