PT-2025-47328 · Checkmk · Checkmk

Published

2025-11-18

·

Updated

2025-11-24

·

CVE-2025-64996

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.4.0p16 Checkmk versions prior to 2.3.0p41 Checkmk versions 2.2.0 and older
Description The mk inotify plugin creates files that are world-readable and writable. This allows any local user on the system to read the plugin’s output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data.
Recommendations Update to Checkmk version 2.4.0p16 or later. Update to Checkmk version 2.3.0p41 or later. Update to a version of Checkmk newer than 2.2.0.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2025-64996

Affected Products

Checkmk