PT-2025-20377 · Checkmk · Checkmk

Norman Kühnberger

·

Published

2025-05-08

·

Updated

2025-05-08

·

CVE-2025-3506

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Checkmk versions 2.1.0 through 2.3.0 Checkmk version 2.4.0b6 and earlier
Description The issue allows files to be deployed with agents to be accessible without authentication. This could enable an attacker to access files that may contain secrets.
Recommendations For Checkmk versions 2.1.0 through 2.3.0, update to a version later than 2.3.0 to resolve the issue. For Checkmk version 2.4.0b6 and earlier, update to a version later than 2.4.0b6 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-3506

Affected Products

Checkmk