Show filters
77 Total Results
Displaying 31-40 of 77
Sort by:
Attacker Value
Unknown

CVE-2024-0670

Disclosure Date: March 11, 2024 (last updated December 21, 2024)
Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges
Attacker Value
Unknown

CVE-2023-6740

Disclosure Date: January 12, 2024 (last updated July 24, 2024)
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
Attacker Value
Unknown

CVE-2023-6735

Disclosure Date: January 12, 2024 (last updated July 24, 2024)
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
Attacker Value
Unknown

CVE-2023-31211

Disclosure Date: January 12, 2024 (last updated July 24, 2024)
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
Attacker Value
Unknown

CVE-2023-31210

Disclosure Date: December 13, 2023 (last updated July 24, 2024)
Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries
Attacker Value
Unknown

CVE-2023-6287

Disclosure Date: November 27, 2023 (last updated December 01, 2023)
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.
Attacker Value
Unknown

CVE-2023-6251

Disclosure Date: November 24, 2023 (last updated July 24, 2024)
Cross-site Request Forgery (CSRF) in Checkmk < 2.2.0p15, < 2.1.0p37, <= 2.0.0p39 allow an authenticated attacker to delete user-messages for individual users.
Attacker Value
Unknown

CVE-2023-6157

Disclosure Date: November 22, 2023 (last updated July 24, 2024)
Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
Attacker Value
Unknown

CVE-2023-6156

Disclosure Date: November 22, 2023 (last updated July 24, 2024)
Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
Attacker Value
Unknown

CVE-2023-23549

Disclosure Date: November 15, 2023 (last updated July 24, 2024)
Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial denial of service of the UI via too long hostnames.