PT-2024-22601 · Checkmk · Checkmk

CVE-2024-28833

·

Published

2024-06-10

·

Updated

2024-07-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Checkmk versions 2.3 through 2.3.0p5
Description The issue is related to improper restriction of excessive authentication attempts with two factor authentication methods, which facilitates brute-forcing of second factor mechanisms.
Recommendations For Checkmk versions 2.3 through 2.3.0p5, update to version 2.3.0p6 or later to resolve the issue.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28833

Affected Products

Checkmk