Checkmk

Vendor:

First CVE: Mar 25, 2022 · Active for 4 years

28
Total CVEs
More Total CVEs than 96% of tracked products
9.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Checkmk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2022
4 years ago
Most Recent CVE
Jan 12, 2024
925 days ago

CVE Severity & Scoring

Checkmk28 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local10 (35.7%)
Network18 (64.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (96.4%)
High1 (3.6%)
Unknown0 (0.0%)
User Interaction
None24 (85.7%)
Unknown0 (0.0%)
Required4 (14.3%)
Privileges Required
Low20 (71.4%)
High2 (7.1%)
None6 (21.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making
Mar 25, 20228.832NONO
Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when commu
Feb 20, 20239.829NONO
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP
Feb 20, 20238.829NONO
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for au
May 17, 20238.827NONO
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
Apr 18, 20238.826NONO
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0
Jan 26, 20238.125NONO
A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected.
Jun 17, 20227.825NONO
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.
Aug 10, 20238.824NONO
Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an
Feb 20, 20237.824NONO
Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Management permissions, as well as
Feb 20, 20237.524NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Checkmk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.6.0p1836.00.8%00
1.6.0p1736.00.8%00
1.6.0p1626.00.7%00
1.6.0p1526.00.7%00
1.6.0p1426.00.7%00
1.6.0p1326.00.7%00
1.6.0p1226.00.7%00
1.6.0p1126.00.7%00
1.6.0p1036.00.8%00
1.6.0b1146.50.6%00
1.6.0b1046.50.6%00