PT-2024-22593 · Checkmk · Checkmk

Published

2024-04-24

·

Updated

2024-12-09

·

CVE-2024-28825

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.3.0b5 Checkmk versions prior to 2.2.0p26 Checkmk versions prior to 2.1.0p43 Checkmk version 2.0.0
Description The issue is related to improper restriction of excessive authentication attempts on some authentication methods, which facilitates password brute-forcing.
Recommendations For versions prior to 2.3.0b5, update to version 2.3.0b5 or later. For versions prior to 2.2.0p26, update to version 2.2.0p26 or later. For versions prior to 2.1.0p43, update to version 2.1.0p43 or later. For version 2.0.0, consider upgrading to a supported version, as 2.0.0 is end-of-life.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2024-28825

Affected Products

Checkmk