PT-2023-14900 · Checkmk · Checkmk
Published
2023-02-20
·
Updated
2024-07-23
·
CVE-2022-46303
CVSS v3.1
8.0
High
| Vector | AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Checkmk versions 1.6.0 through 1.6.0p29
Checkmk versions 2.0.0 through 2.0.0p27
Checkmk versions 2.1.0 through 2.1.0p10
Description
The issue allows an attacker with User Management permissions, as well as LDAP administrators in certain scenarios, to perform arbitrary commands within the context of the application's local permissions due to command injection in SMS notifications.
Recommendations
For Checkmk versions 1.6.0 through 1.6.0p29, update to a version later than 1.6.0p29 to resolve the issue.
For Checkmk versions 2.0.0 through 2.0.0p27, update to a version later than 2.0.0p27 to resolve the issue.
For Checkmk versions 2.1.0 through 2.1.0p10, update to a version later than 2.1.0p10 to resolve the issue.
As a temporary workaround, consider restricting access to SMS notifications and User Management permissions to minimize the risk of exploitation.
Fix
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Checkmk