Search

Find a vulnerability

Search criteria

    16 vulnerabilities by Checkmk

    CVE-2024-13722 (GCVE-0-2024-13722)

    Vulnerability from cvelistv5 – Published: 2025-02-04 22:04 – Updated: 2025-11-03 19:29
    VLAI
    Title
    Checkmk NagVis Reflected Cross-site Scripting
    Summary
    The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 14:56 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
    Impacted products
    Vendor Product Version
    Checkmk NagVis Affected: NagVis 1.9.40 , < 1.9.42 (semver)
    Affected: Checkmk 2.3.0p2 , < 2.3.0p10 (semver)
    Create a notification for this product.
    Date Public
    2025-02-04 22:03
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:29:15.962Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://seclists.org/fulldisclosure/2025/Feb/3"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2025/02/04/3"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00000.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 5.4,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "LOW",
                  "scope": "CHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-13722",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T14:56:14.228335Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-06T14:30:21.913Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://korelogic.com/Resources/Advisories/KL-001-2025-001.txt"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Linux"
              ],
              "product": "NagVis",
              "vendor": "Checkmk",
              "versions": [
                {
                  "lessThan": "1.9.42",
                  "status": "affected",
                  "version": "NagVis 1.9.40",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.3.0p10",
                  "status": "affected",
                  "version": "Checkmk 2.3.0p2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This vulnerability was discovered by Jaggar Henry and Jim Becher of KoreLogic, Inc."
            }
          ],
          "datePublic": "2025-02-04T22:03:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The \"NagVis\" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users."
                }
              ],
              "value": "The \"NagVis\" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or \u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-04T22:04:00.315Z",
            "orgId": "bbf0bd87-ece2-41be-b873-96928ee8fab9",
            "shortName": "KoreLogic"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://korelogic.com/Resources/Advisories/KL-001-2025-001.txt"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://www.nagvis.org/downloads/changelog/1.9.42"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://checkmk.com/werks?version=2.3.0p10"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Checkmk NagVis Reflected Cross-site Scripting",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bbf0bd87-ece2-41be-b873-96928ee8fab9",
        "assignerShortName": "KoreLogic",
        "cveId": "CVE-2024-13722",
        "datePublished": "2025-02-04T22:04:00.315Z",
        "dateReserved": "2025-01-24T18:22:32.696Z",
        "dateUpdated": "2025-11-03T19:29:15.962Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-13723 (GCVE-0-2024-13723)

    Vulnerability from cvelistv5 – Published: 2025-02-04 22:02 – Updated: 2025-11-03 19:29
    VLAI
    Title
    Checkmk NagVis Remote Code Execution
    Summary
    The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 15:38 UTC
    CWE
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    Impacted products
    Vendor Product Version
    Checkmk NagVis Affected: NagVis 1.9.40 , < 1.9.42 (semver)
    Affected: Checkmk 2.3.0p2 , < 2.3.0p10 (semver)
    Create a notification for this product.
    Date Public
    2025-02-04 22:01
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:29:17.332Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://seclists.org/fulldisclosure/2025/Feb/4"
              },
              {
                "url": "http://www.openwall.com/lists/oss-security/2025/02/04/4"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00000.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.2,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-13723",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T15:38:27.695468Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-06T14:43:37.316Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://korelogic.com/Resources/Advisories/KL-001-2025-002.txt"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Linux"
              ],
              "product": "NagVis",
              "vendor": "Checkmk",
              "versions": [
                {
                  "lessThan": "1.9.42",
                  "status": "affected",
                  "version": "NagVis 1.9.40",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.3.0p10",
                  "status": "affected",
                  "version": "Checkmk 2.3.0p2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "This vulnerability was discovered by Jaggar Henry and Jim Becher of KoreLogic, Inc."
            }
          ],
          "datePublic": "2025-02-04T22:01:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The \"NagVis\" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "The \"NagVis\" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-04T22:02:19.226Z",
            "orgId": "bbf0bd87-ece2-41be-b873-96928ee8fab9",
            "shortName": "KoreLogic"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://korelogic.com/Resources/Advisories/KL-001-2025-002.txt"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://www.nagvis.org/downloads/changelog/1.9.42"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://checkmk.com/werks?version=2.3.0p10"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Checkmk NagVis Remote Code Execution",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "bbf0bd87-ece2-41be-b873-96928ee8fab9",
        "assignerShortName": "KoreLogic",
        "cveId": "CVE-2024-13723",
        "datePublished": "2025-02-04T22:02:19.226Z",
        "dateReserved": "2025-01-24T18:22:56.194Z",
        "dateUpdated": "2025-11-03T19:29:17.332Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-6747 (GCVE-0-2024-6747)

    Vulnerability from cvelistv5 – Published: 2024-10-10 07:43 – Updated: 2024-10-10 13:44
    VLAI
    Title
    Information leak in mknotifyd
    Summary
    Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-10 13:39 UTC
    CWE
    • CWE-201 - Insertion of Sensitive Information Into Sent Data
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0p18 (semver)
    Affected: 2.2.0 , < 2.2.0p36 (semver)
    Affected: 2.1.0 , < 2.1.0p49 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0p18 (semver)
    Affected: 2.2.0 , < 2.2.0p36 (semver)
    Affected: 2.1.0 , < 2.1.0p49 (semver)
    Affected: 2.0.0 , < 2.0.0p39 (semver)
        cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0p18",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.2.0p36",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.1.0p49",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6747",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-10T13:39:42.762205Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-10T13:44:21.470Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0p18",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p36",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p49",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-277",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-277: Data Interchange Protocol Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-201",
                  "description": "CWE-201: Insertion of Sensitive Information Into Sent Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-10T07:43:48.050Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/17145"
            }
          ],
          "title": "Information leak in mknotifyd"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-6747",
        "datePublished": "2024-10-10T07:43:48.050Z",
        "dateReserved": "2024-07-15T11:36:34.147Z",
        "dateUpdated": "2024-10-10T13:44:21.470Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-8606 (GCVE-0-2024-8606)

    Vulnerability from cvelistv5 – Published: 2024-09-23 07:01 – Updated: 2024-09-23 15:33
    VLAI
    Title
    Fix 2FA bypass via RestAPI
    Summary
    Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-23 15:32 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0p16 (semver)
    Affected: 2.2.0 , < 2.2.0p34 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0p16 (semver)
    Affected: 2.2.0 , < 2.2.0p34 (custom)
        cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0p16",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.2.0p34",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8606",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-23T15:32:23.848819Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-23T15:33:22.875Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0p16",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p34",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Bypass of two factor authentication in RestAPI in Checkmk \u003c 2.3.0p16 and \u003c 2.2.0p34 allows authenticated users to bypass two factor authentication"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115: Authentication Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-23T07:01:04.769Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/16218"
            }
          ],
          "title": "Fix 2FA bypass via RestAPI"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-8606",
        "datePublished": "2024-09-23T07:01:04.769Z",
        "dateReserved": "2024-09-09T09:39:58.785Z",
        "dateUpdated": "2024-09-23T15:33:22.875Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6572 (GCVE-0-2024-6572)

    Vulnerability from cvelistv5 – Published: 2024-09-09 09:39 – Updated: 2024-09-09 13:03
    VLAI
    Title
    Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'
    Summary
    Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-09 12:57 UTC
    CWE
    • CWE-322 - Key Exchange without Entity Authentication
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0p15 (semver)
    Affected: 2.2.0 , < 2.2.0p33 (semver)
    Affected: 2.1.0 , < 2.1.0p48 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0p15 (semver)
    Affected: 2.2.0 , < 2.2.0p33 (semver)
    Affected: 2.1.0 , < 2.1.0p48 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
        cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0p15",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.2.0p33",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.1.0p48",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 7.4,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6572",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-09T12:57:41.533717Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-09T13:03:22.065Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0p15",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p33",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p48",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper host key checking in active check \u0027Check SFTP Service\u0027 and special agent \u0027VNX quotas and filesystem\u0027 in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-94",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-94: Adversary in the Middle (AiTM)"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-322",
                  "description": "CWE-322: Key Exchange without Entity Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-09T09:39:17.769Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/17148"
            }
          ],
          "title": "Improper host key checking in active check \u0027Check SFTP Service\u0027 and special agent \u0027VNX quotas and filesystem\u0027"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-6572",
        "datePublished": "2024-09-09T09:39:17.769Z",
        "dateReserved": "2024-07-08T15:50:02.376Z",
        "dateUpdated": "2024-09-09T13:03:22.065Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28829 (GCVE-0-2024-28829)

    Vulnerability from cvelistv5 – Published: 2024-08-20 09:29 – Updated: 2024-08-21 19:37
    VLAI
    Title
    Privilege escalation in mk_informix plugin
    Summary
    Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-21 19:30 UTC
    CWE
    • CWE-272 - Least Privilege Violation
    • CWE-807 - Reliance on Untrusted Inputs in a Security Decision
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0p12 (semver)
    Affected: 2.2.0 , < 2.2.0p32 (semver)
    Affected: 2.1.0 , < 2.1.0p47 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0p12 (custom)
    Affected: 2.2.0 , < 2.2.0p32 (custom)
    Affected: 2.1.0 , < 2.1.0p47 (custom)
    Affected: 2.0.0 , ≤ 2.0.0p39 (custom)
        cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0p12",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "2.2.0p32",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "2.1.0p47",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28829",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-21T19:30:50.880166Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-21T19:37:32.708Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0p12",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p32",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p47",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.2,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H",
                "version": "4.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-272",
                  "description": "CWE-272: Least Privilege Violation",
                  "lang": "en",
                  "type": "CWE"
                },
                {
                  "cweId": "CWE-807",
                  "description": "CWE-807: Reliance on Untrusted Inputs in a Security Decision",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-20T09:29:26.474Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/16249"
            }
          ],
          "title": "Privilege escalation in mk_informix plugin"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-28829",
        "datePublished": "2024-08-20T09:29:26.474Z",
        "dateReserved": "2024-03-11T13:21:43.122Z",
        "dateUpdated": "2024-08-21T19:37:32.708Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6542 (GCVE-0-2024-6542)

    Vulnerability from cvelistv5 – Published: 2024-07-22 09:50 – Updated: 2024-08-01 21:41
    VLAI
    Title
    Livestatus injection in mknotifyd
    Summary
    Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-22 13:29 UTC
    CWE
    • CWE-140 - Improper Neutralization of Delimiters
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0p11 (semver)
    Affected: 2.2.0 , < 2.2.0p32 (semver)
    Affected: 2.1.0 , < 2.1.0p47 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Affected: 2.1.0 , < 2.1.0p47 (semver)
    Affected: 2.2.0 , < 2.2.0p32 (semver)
    Affected: 2.3.0 , < 2.3.0p11 (semver)
        cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThanOrEqual": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.1.0p47",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.2.0p32",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.3.0p11",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6542",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-22T13:29:23.832484Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-22T20:26:27.733Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T21:41:03.497Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://checkmk.com/werk/17013"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0p11",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p32",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p47",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk \u003c= 2.0.0p39, \u003c 2.1.0p47, \u003c 2.2.0p32 and \u003c 2.3.0p11 allows arbitrary livestatus command execution."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-15",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-15: Command Delimiters"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-140",
                  "description": "CWE-140: Improper Neutralization of Delimiters",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-22T09:50:17.736Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/17013"
            }
          ],
          "title": "Livestatus injection in mknotifyd"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-6542",
        "datePublished": "2024-07-22T09:50:17.736Z",
        "dateReserved": "2024-07-08T11:59:16.981Z",
        "dateUpdated": "2024-08-01T21:41:03.497Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28828 (GCVE-0-2024-28828)

    Vulnerability from cvelistv5 – Published: 2024-07-10 12:41 – Updated: 2024-08-02 00:56
    VLAI
    Title
    1-Click compromize via CSRF
    Summary
    Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-10 13:13 UTC
    CWE
    • CWE-352 - Cross-Site Request Forgery (CSRF)
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0p8 (semver)
    Affected: 2.2.0 , < 2.2.0p29 (semver)
    Affected: 2.1.0 , < 2.1.0p45 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0p8 (semver)
    Affected: 2.2.0 , < 2.2.0p29 (semver)
    Affected: 2.1.0 , < 2.1.0p45 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
        cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0p8",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.2.0p29",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.1.0p45",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28828",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-10T13:13:26.418829Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-10T20:17:11.996Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:56:58.057Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://checkmk.com/werk/17090"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0p8",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p29",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p45",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "PS Positive Security GmbH"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Cross-Site request forgery in Checkmk \u003c 2.3.0p8, \u003c 2.2.0p29, \u003c 2.1.0p45, and \u003c= 2.0.0p39 (EOL) could lead to 1-click compromize of the site."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-62",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-62: Cross Site Request Forgery"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-352",
                  "description": "CWE-352: Cross-Site Request Forgery (CSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-10T12:41:13.934Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/17090"
            }
          ],
          "title": "1-Click compromize via CSRF"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-28828",
        "datePublished": "2024-07-10T12:41:13.934Z",
        "dateReserved": "2024-03-11T13:21:43.122Z",
        "dateUpdated": "2024-08-02T00:56:58.057Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28827 (GCVE-0-2024-28827)

    Vulnerability from cvelistv5 – Published: 2024-07-10 12:41 – Updated: 2024-08-02 00:56
    VLAI
    Title
    Privilege escalation in Windows agent
    Summary
    Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a local attacker to gain SYSTEM privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-10 13:10 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0p8 (semver)
    Affected: 2.2.0 , < 2.2.0p29 (semver)
    Affected: 2.1.0 , < 2.1.0p45 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.0.0 , ≤ 2.0.0p39 (custom)
        cpe:2.3:a:checkmk:checkmk:2.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.1.0 , < 2.1.0p45 (custom)
        cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.2.0 , < 2.2.0p29 (custom)
        cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0p8 (custom)
        cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThanOrEqual": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.1.0p45",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.2.0p29",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0p8",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28827",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-10T13:10:28.297013Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-11T16:31:48.895Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:56:58.208Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://checkmk.com/werk/16845"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0p8",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p29",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p45",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "modzero GmbH"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Incorrect permissions on the Checkmk Windows Agent\u0027s data directory in Checkmk \u003c 2.3.0p8, \u003c 2.2.0p29, \u003c 2.1.0p45, and \u003c= 2.0.0p39 (EOL) allows a local attacker to gain SYSTEM privileges."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233: Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732: Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-10T12:41:04.948Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/16845"
            }
          ],
          "title": "Privilege escalation in Windows agent"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-28827",
        "datePublished": "2024-07-10T12:41:04.948Z",
        "dateReserved": "2024-03-11T13:21:43.122Z",
        "dateUpdated": "2024-08-02T00:56:58.208Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28833 (GCVE-0-2024-28833)

    Vulnerability from cvelistv5 – Published: 2024-06-10 11:55 – Updated: 2024-08-02 00:56
    VLAI
    Title
    Missing brute-force protection for two factor authentication
    Summary
    Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-10 18:04 UTC
    CWE
    • CWE-307 - Improper Restriction of Excessive Authentication Attempts
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0p6 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0p6 (semver)
        cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0p6",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28833",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-10T18:04:29.500256Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-19T22:52:07.799Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:56:58.393Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://checkmk.com/werk/16830"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0p6",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "PS Positive Security GmbH"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-112",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-112: Brute Force"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "CWE-307: Improper Restriction of Excessive Authentication Attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-19T08:12:15.306Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/16830"
            }
          ],
          "title": "Missing brute-force protection for two factor authentication"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-28833",
        "datePublished": "2024-06-10T11:55:50.571Z",
        "dateReserved": "2024-03-11T13:21:43.122Z",
        "dateUpdated": "2024-08-02T00:56:58.393Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28826 (GCVE-0-2024-28826)

    Vulnerability from cvelistv5 – Published: 2024-05-29 10:00 – Updated: 2024-08-02 00:56
    VLAI
    Title
    Unrestricted upload and download paths in check_sftp
    Summary
    Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-05 20:21 UTC
    CWE
    • CWE-73 - External Control of File Name or Path
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0p4 (semver)
    Affected: 2.2.0 , < 2.2.0p27 (semver)
    Affected: 2.1.0 , < 2.1.0p44 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.0.0 , < 2.0.0p39 (semver)
        cpe:2.3:a:checkmk:checkmk:2.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.1.0 , < 2.1.0p44 (semver)
        cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.2.0 , < 2.2.0p27 (semver)
        cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0p4 (semver)
        cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.1.0p44",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.2.0p27",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0p4",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28826",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-05T20:21:05.131648Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-05T20:33:54.922Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:56:58.127Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://checkmk.com/werk/15200"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0p4",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p27",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p44",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-212",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-212: Functionality Misuse"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73: External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-29T10:00:53.789Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/15200"
            }
          ],
          "title": "Unrestricted upload and download paths in check_sftp"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-28826",
        "datePublished": "2024-05-29T10:00:53.789Z",
        "dateReserved": "2024-03-11T13:21:43.122Z",
        "dateUpdated": "2024-08-02T00:56:58.127Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28825 (GCVE-0-2024-28825)

    Vulnerability from cvelistv5 – Published: 2024-04-24 11:25 – Updated: 2024-08-02 00:56
    VLAI
    Title
    Brute-force protection ineffective for some login methods
    Summary
    Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitates password brute-forcing.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-24 14:27 UTC
    CWE
    • CWE-307 - Improper Restriction of Excessive Authentication Attempts
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0b5 (semver)
    Affected: 2.2.0 , < 2.2.0p26 (semver)
    Affected: 2.1.0 , < 2.1.0p43 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.0.0 , < 2.0.0p39 (semver)
        cpe:2.3:a:checkmk:checkmk:2.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.1.0 , < 2.1.0p43 (semver)
        cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.2.0 , < 2.2.0p26 (semver)
        cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0b5 (semver)
        cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.1.0p43",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.2.0p26",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0b5",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28825",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-24T14:27:40.480273Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T18:03:50.090Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:56:58.650Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://checkmk.com/werk/15198"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0b5",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p26",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p43",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitates password brute-forcing."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-49",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-49: Password Brute Forcing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "CWE-307: Improper Restriction of Excessive Authentication Attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-04-24T11:25:36.306Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/15198"
            }
          ],
          "title": "Brute-force protection ineffective for some login methods"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-28825",
        "datePublished": "2024-04-24T11:25:36.306Z",
        "dateReserved": "2024-03-11T13:21:43.122Z",
        "dateUpdated": "2024-08-02T00:56:58.650Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3367 (GCVE-0-2024-3367)

    Vulnerability from cvelistv5 – Published: 2024-04-16 11:59 – Updated: 2024-08-26 09:48
    VLAI
    Title
    Argument injection to runmqsc
    Summary
    Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmqsc
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-24 14:21 UTC
    CWE
    • CWE-88 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0b5 (semver)
    Affected: 2.2.0 , < 2.2.0p26 (semver)
    Affected: 2.1.0 , < 2.1.0p99 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.0.0 , < 2.0.0p39 (semver)
        cpe:2.3:a:checkmk:checkmk:2.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.1.0 , < 2.1.0p99 (semver)
        cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.2.0 , < 2.2.0p26 (semver)
        cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0b5 (semver)
        cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.1.0p99",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.2.0p26",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0b5",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3367",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-24T14:21:12.926526Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-13T20:39:25.120Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:05:08.548Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://checkmk.com/werk/16615"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0b5",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p26",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p99",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, \u003c2.2.0p26 and \u003c2.3.0b5 allows local attacker to inject one argument to runmqsc"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-6",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-6: Argument Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-88",
                  "description": "CWE-88: Improper Neutralization of Argument Delimiters in a Command (\u0027Argument Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-26T09:48:37.438Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/16615"
            }
          ],
          "title": "Argument injection to runmqsc"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-3367",
        "datePublished": "2024-04-16T11:59:43.845Z",
        "dateReserved": "2024-04-05T08:38:32.436Z",
        "dateUpdated": "2024-08-26T09:48:37.438Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-1742 (GCVE-0-2024-1742)

    Vulnerability from cvelistv5 – Published: 2024-03-22 10:26 – Updated: 2024-08-12 18:34
    VLAI
    Title
    Information disclosure in mk_oracle Checkmk agent plugin
    Summary
    Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-28 19:12 UTC
    CWE
    • CWE-214 - Invocation of Process Using Visible Sensitive Information
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0b4 (semver)
    Affected: 2.2.0 , < 2.2.0p24 (semver)
    Affected: 2.1.0 , < 2.1.0p41 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0b4 (semver)
    Affected: 2.2.0 , < 2.2.0p24 (semver)
    Affected: 2.1.0 , < 2.1.0p41 (semver)
    Affected: 2.0.0 , < 2.0.0p39 (semver)
        cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:48:21.919Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://checkmk.com/werk/16234"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0b4",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.2.0p24",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.1.0p41",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1742",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-28T19:12:10.406234Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-12T18:34:37.823Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0b4",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p24",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p41",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-150",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-150: Collect Data from Common Resource Locations"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 3.8,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-214",
                  "description": "CWE-214: Invocation of Process Using Visible Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-22T10:26:06.238Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/16234"
            }
          ],
          "title": "Information disclosure in mk_oracle Checkmk agent plugin"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-1742",
        "datePublished": "2024-03-22T10:26:06.238Z",
        "dateReserved": "2024-02-22T12:43:58.785Z",
        "dateUpdated": "2024-08-12T18:34:37.823Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0638 (GCVE-0-2024-0638)

    Vulnerability from cvelistv5 – Published: 2024-03-22 10:25 – Updated: 2024-08-02 14:54
    VLAI
    Title
    Privilege escalation in mk_oracle plugins
    Summary
    Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-02 14:50 UTC
    CWE
    • CWE-272 - Least Privilege Violation
    References
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.3.0 , < 2.3.0b4 (semver)
    Affected: 2.2.0 , < 2.2.0p24 (semver)
    Affected: 2.1.0 , < 2.1.0p41 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.3.0 , < 2.3.0b4 (semver)
    Affected: 2.2.0 , < 2.2.0p24 (semver)
    Affected: 2.1.0 , < 2.1.0p41 (semver)
    Affected: 2.0.0 , < 2.0.0p39 (semver)
        cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:11:35.679Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://checkmk.com/werk/16232"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.3.0b4",
                    "status": "affected",
                    "version": "2.3.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.2.0p24",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.1.0p41",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0638",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-02T14:50:20.039040Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-02T14:54:20.182Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.3.0b4",
                  "status": "affected",
                  "version": "2.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.2.0p24",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p41",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-272",
                  "description": "CWE-272: Least Privilege Violation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-22T10:25:35.675Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/16232"
            }
          ],
          "title": "Privilege escalation in mk_oracle plugins"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-0638",
        "datePublished": "2024-03-22T10:25:35.675Z",
        "dateReserved": "2024-01-17T09:09:03.629Z",
        "dateUpdated": "2024-08-02T14:54:20.182Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0670 (GCVE-0-2024-0670)

    Vulnerability from cvelistv5 – Published: 2024-03-11 14:50 – Updated: 2025-02-13 17:27
    VLAI
    Title
    Privilege escalation in windows agent
    Summary
    Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 18:21 UTC
    CWE
    • CWE-427 - Uncontrolled Search Path Element
    Impacted products
    Vendor Product Version
    Checkmk GmbH Checkmk Affected: 2.2.0 , < 2.2.0p23 (semver)
    Affected: 2.1.0 , < 2.1.0p40 (semver)
    Affected: 2.0.0 , ≤ 2.0.0p39 (semver)
    Create a notification for this product.
    checkmk checkmk Affected: 2.2.0 , < 2.2.0p23 (semver)
    Affected: 2.1.0 , < 2.1.0p40 (semver)
    Affected: 2.0.0 , < 2.0.0p39 (semver)
        cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:11:35.672Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://checkmk.com/werk/16361"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://seclists.org/fulldisclosure/2024/Mar/29"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "checkmk",
                "vendor": "checkmk",
                "versions": [
                  {
                    "lessThan": "2.2.0p23",
                    "status": "affected",
                    "version": "2.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.1.0p40",
                    "status": "affected",
                    "version": "2.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "2.0.0p39",
                    "status": "affected",
                    "version": "2.0.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0670",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T18:21:01.803225Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-12T18:36:03.818Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Checkmk",
              "vendor": "Checkmk GmbH",
              "versions": [
                {
                  "lessThan": "2.2.0p23",
                  "status": "affected",
                  "version": "2.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2.1.0p40",
                  "status": "affected",
                  "version": "2.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "2.0.0p39",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-427",
                  "description": "CWE-427 Uncontrolled Search Path Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-13T22:08:42.967Z",
            "orgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
            "shortName": "Checkmk"
          },
          "references": [
            {
              "url": "https://checkmk.com/werk/16361"
            },
            {
              "url": "http://seclists.org/fulldisclosure/2024/Mar/29"
            }
          ],
          "title": "Privilege escalation in windows agent"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f7d6281c-4801-44ce-ace2-493291dedb0f",
        "assignerShortName": "Checkmk",
        "cveId": "CVE-2024-0670",
        "datePublished": "2024-03-11T14:50:59.415Z",
        "dateReserved": "2024-01-18T09:51:30.688Z",
        "dateUpdated": "2025-02-13T17:27:13.277Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }