« Volver al listado

CVE-2025-2028

Estado: AnalizadaMedia (5.3)—

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-2028",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-2028",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-06T15:05:10.377561Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@checkpoint.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@checkpoint.com",
      "affectedData": [
        {
          "vendor": "checkpoint",
          "product": "Check Point Management Log Server",
          "versions": [
            {
              "status": "affected",
              "version": "versions R81.10, R81.20, R82"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-08-06T15:15:31.657",
  "references": [
    {
      "url": "https://support.checkpoint.com/results/sk/sk183349",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@checkpoint.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@checkpoint.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs"
    },
    {
      "lang": "es",
      "value": "Falta de validación TLS al descargar un archivo CSV que incluye la asignación de IP a países utilizados SÓLO para mostrar banderas de países en los registros"
    }
  ],
  "lastModified": "2026-06-17T09:06:06.270",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkpoint:log_server:r81.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EAEF6DCB-389A-494F-BA10-7D4A9739A585"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:log_server:r81.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9726550F-4150-463B-8F43-CEF283B75903"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:log_server:r82:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EAFBC6AB-7584-49E3-ADAC-32300807A4C1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@checkpoint.com"
}