> Source: [sk183761](https://support.checkpoint.com/results/sk/sk183761)

# sk183761 - Check Point Response to CVE-2025-3831 - Exposed SFTP server

| Property | Value |
|----------|-------|
| Solution ID | sk183761 |
| Date Created | 2025-08-12 |
| Last Modified | 2025-08-12 |
| Technical Level | General |
| Products | SASE |
| Versions | Cloud |

## Symptoms

- * Log files uploaded by the Harmony SASE agent during troubleshooting may have been accessible to unauthorized parties. These logs could include temporary authentication tokens.
* This issue received the ID [CVE-2025-3831](https://www.cve.org/CVERecord?id=CVE-2025-3831)

## Cause

The agent used a shared SFTP key embedded in the software to upload diagnostic logs. The key was granted permission to read and list files on the server, rather than restricted to upload-only access. As a result, anyone possessing the key could access log files uploaded by other customers.

## Solution

A researcher who identified and disclosed this issue contacted Check Point on March 22, 2025. As soon as the issue was responsibly disclosed to Check Point, the SFTP key's permissions were immediately downgraded to write-only.   

No action is required on the customer side.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
