Check Mk

Vendor:

First CVE: Aug 22, 2014 · Active for 11 years

10
Total CVEs
More Total CVEs than 88% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Check Mk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2014
11 years ago
Most Recent CVE
Jul 19, 2018
2,929 days ago

CVE Severity & Scoring

Check Mk10 CVEs
All CVEs352,713 CVEs
LowMediumHigh
Attack Vector
Local1 (10.0%)
Network2 (20.0%)
Unknown7 (70.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (30.0%)
High0 (0.0%)
Unknown7 (70.0%)
User Interaction
None1 (10.0%)
Unknown7 (70.0%)
Required2 (20.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None2 (20.0%)
Unknown7 (70.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted
Sep 2, 20149.331NONO
Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authentication of users for requests
Aug 31, 20156.823NONO
Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. NOTE: this can be exploited by
Aug 31, 20158.522NONO
A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript v
Jun 21, 20176.121NONO
Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk files) to arbitrary locations via vectors related to row sele
Sep 2, 20144.920NONO
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
Jul 19, 20185.517NONO
A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.2.8x prior to 1.2.8p25 and 1.4.0x prior to 1.4.0p9, allowing an unauthenticated attacker to inject arbitrar
Dec 11, 20176.117NONO
Multiple cross-site scripting (XSS) vulnerabilities in the multisite component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allow remote authenticated users to inject arbitr
Aug 22, 20143.517NONO
Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to "Insecure Direct Obje
Aug 31, 20155.516NONO
Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject arbitrary web script or HTML via
Aug 31, 20153.513NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Check Mk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.4.026.11.2%00
1.2.816.11.0%00
1.2.545.93.0%00
1.2.435.73.1%00