TROYANOSYVIRUS
Retour aux CVEs

CVE-2024-28826

HIGH
8.8

Description

Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.

Details CVE

Score CVSS v3.18.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie5/29/2024
Derniere modification12/4/2024
Sourcenvd
Observations honeypot0

Produits affectes

checkmk:checkmk

Faiblesses (CWE)

CWE-73CWE-610

References

https://checkmk.com/werk/15200(security@checkmk.com)
https://checkmk.com/werk/15200(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.