PT-2024-37423 · Checkmk · Checkmk
Published
2024-07-08
·
Updated
2024-08-20
·
CVE-2024-6163
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Checkmk versions prior to 2.3.0p10
Checkmk versions prior to 2.2.0p31
Checkmk versions prior to 2.1.0p46
Checkmk versions prior to or equal to 2.0.0p39
Description:
The issue allows a remote attacker to bypass authentication and access data through certain HTTP endpoints of Checkmk.
Recommendations:
For versions prior to 2.3.0p10, update to version 2.3.0p10 or later.
For versions prior to 2.2.0p31, update to version 2.2.0p31 or later.
For versions prior to 2.1.0p46, update to version 2.1.0p46 or later.
For versions prior to or equal to 2.0.0p39, update to a version later than 2.0.0p39.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk