CVE-2025-3831 PUBLISHED

Exposed SFTP server

Assigner: checkpoint
Reserved: 20.04.2025 Published: 12.08.2025 Updated: 12.08.2025

Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor checkpoint
Product Check Point Harmony SASE
Versions
  • Version Other is affected

References

Problem Types

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor. CWE
  • CWE-798: Use of Hard-coded Credentials. CWE