5.9

CVE-2017-14955

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CheckmkCheckmk Version1.2.3 Updatei6
CheckmkCheckmk Version1.2.3 Updatei7
CheckmkCheckmk Version1.2.4 Updateb1
CheckmkCheckmk Version1.2.5 Updatei1
CheckmkCheckmk Version1.2.5 Updatei2
CheckmkCheckmk Version1.2.5 Updatei3
CheckmkCheckmk Version1.2.5 Updatei4
CheckmkCheckmk Version1.2.5 Updatei5
CheckmkCheckmk Version1.2.5 Updatei6
CheckmkCheckmk Version1.2.6 Updateb1
CheckmkCheckmk Version1.2.6 Updateb2
CheckmkCheckmk Version1.2.6 Updatep13
CheckmkCheckmk Version1.2.7 Updatei1
CheckmkCheckmk Version1.2.7 Updatei1p2
CheckmkCheckmk Version1.2.7 Updatei2
CheckmkCheckmk Version1.2.7 Updatei3
CheckmkCheckmk Version1.2.7 Updatei4
CheckmkCheckmk Version1.2.8 Updatep18
CheckmkCheckmk Version1.2.8 Updatep25
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.62% 0.953
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.