Checkmk
Vendor:
First CVE: Mar 25, 2022 · Active for 4 years
28
Total CVEs
More Total CVEs than 96% of tracked products
9.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Checkmk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2022
4 years ago
Most Recent CVE
Jan 12, 2024
925 days ago
CVE Severity & Scoring
Checkmk28 CVEs
46%
46%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (35.7%)
Network18 (64.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (96.4%)
High1 (3.6%)
Unknown0 (0.0%)
User Interaction
None24 (85.7%)
Unknown0 (0.0%)
Required4 (14.3%)
Privileges Required
Low20 (71.4%)
High2 (7.1%)
None6 (21.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40905HIGH The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making | Mar 25, 2022 | 8.8 | 32 | NO | NO |
CVE-2022-48317CRITICAL Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when commu | Feb 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-46836HIGH PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP | Feb 20, 2023 | 8.8 | 29 | NO | NO |
CVE-2023-31208HIGH Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for au | May 17, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-22294HIGH Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions. | Apr 18, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-0284HIGH Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0 | Jan 26, 2023 | 8.1 | 25 | NO | NO |
CVE-2022-33912HIGH A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. | Jun 17, 2022 | 7.8 | 25 | NO | NO |
CVE-2023-31209HIGH Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users. | Aug 10, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-47909HIGH Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an | Feb 20, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-46303HIGH Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Management permissions, as well as | Feb 20, 2023 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Checkmk
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.6.0p18 | 3 | 6.0 | 0.8% | 0 | 0 |
| 1.6.0p17 | 3 | 6.0 | 0.8% | 0 | 0 |
| 1.6.0p16 | 2 | 6.0 | 0.7% | 0 | 0 |
| 1.6.0p15 | 2 | 6.0 | 0.7% | 0 | 0 |
| 1.6.0p14 | 2 | 6.0 | 0.7% | 0 | 0 |
| 1.6.0p13 | 2 | 6.0 | 0.7% | 0 | 0 |
| 1.6.0p12 | 2 | 6.0 | 0.7% | 0 | 0 |
| 1.6.0p11 | 2 | 6.0 | 0.7% | 0 | 0 |
| 1.6.0p10 | 3 | 6.0 | 0.8% | 0 | 0 |
| 1.6.0b11 | 4 | 6.5 | 0.6% | 0 | 0 |
| 1.6.0b10 | 4 | 6.5 | 0.6% | 0 | 0 |