CVE-2025-2028: Lack of TLS validation
Published Aug 6, 2025
·Updated
Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs
Affected Software
3 affected components
Checkpoint Log Server=r81.10
Checkpoint Log Server=r81.20
Checkpoint Log Server=r82
Event History
Aug 6, 2025
CVE Published
via MITRE·02:44 PM
Data Sourced
via MITRE·02:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2028?
CVE-2025-2028 is considered a medium severity vulnerability due to the potential risk of man-in-the-middle attacks.
2
How do I fix CVE-2025-2028?
To fix CVE-2025-2028, ensure that TLS validation is properly implemented in your system configuration.
3
Which versions are affected by CVE-2025-2028?
CVE-2025-2028 affects Check Point Log Server versions r81.10, r81.20, and r82.
4
What kind of data is compromised in CVE-2025-2028?
CVE-2025-2028 involves a lack of TLS validation when downloading a CSV file containing IP to country mappings.
5
What is the impact of CVE-2025-2028 on logging security?
The impact of CVE-2025-2028 on logging security could lead to exposure of sensitive information through logging functionalities.