Check Point R82
cpe:2.3:o:checkpoint:gaia:*:*:*:*:*:*:*, +1 more
- R81.10
- R81.20
- R82
A vulnerability exists in Check Point products R81.10, R81.20, and R82, due to a lack of proper TLS validation when downloading CSV files that map IP addresses to countries. This data is used solely for displaying country flags in logs. The absence of validation could potentially be exploited in certain scenarios.
Exploitation of this vulnerability could lead to man-in-the-middle attacks, where an attacker could intercept and modify the data being downloaded without detection.
Users can apply the fix included in the Jumbo Hotfix Accumulator for R82 (starting from Take 36), R81.20 (starting from Take 111), or R81.10 (starting from Take 177).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.