CVE-2025-8305

MEDIUM

Identity Agent for Terminal Services - Info Disclosure

Title source: llm
STIX 2.1

Description

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0010
EPSS Percentile 1.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
checkpoint/Identity Awareness Check Point Identity Agent Multi User Host Agent under version 81.084.0000
Published Dec 22, 2025
Tracked Since Feb 18, 2026