PT-2024-37423 · Checkmk · Checkmk

Published

2024-07-08

·

Updated

2024-08-20

·

CVE-2024-6163

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Checkmk versions prior to 2.3.0p10 Checkmk versions prior to 2.2.0p31 Checkmk versions prior to 2.1.0p46 Checkmk versions prior to or equal to 2.0.0p39
Description: The issue allows a remote attacker to bypass authentication and access data through certain HTTP endpoints of Checkmk.
Recommendations: For versions prior to 2.3.0p10, update to version 2.3.0p10 or later. For versions prior to 2.2.0p31, update to version 2.2.0p31 or later. For versions prior to 2.1.0p46, update to version 2.1.0p46 or later. For versions prior to or equal to 2.0.0p39, update to a version later than 2.0.0p39.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6163

Affected Products

Checkmk