PT-2025-52208 · Checkmk · Checkmk

Published

2025-12-18

·

Updated

2025-12-18

·

CVE-2025-64997

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.4.0p17 Checkmk versions prior to 2.3.0p42
Description A flaw exists in permission validation within Checkmk. Low-privileged users can access agent information through the REST API, potentially leading to information disclosure. The vulnerable API endpoint allows unauthorized access to sensitive data. The affected parameter is not specified.
Recommendations Update Checkmk to version 2.4.0p17 or later. Update Checkmk to version 2.3.0p42 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-64997

Affected Products

Checkmk