CVE-2025-1075
- EPSS 0.14%
- Veröffentlicht 19.02.2025 10:15:09
- Zuletzt bearbeitet 25.08.2025 01:19:09
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials to be written to Apache error log file accessible to administrators.
CVE-2024-38864
- EPSS 0.06%
- Veröffentlicht 19.12.2024 16:15:08
- Zuletzt bearbeitet 25.08.2025 14:53:51
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.
CVE-2024-47094
- EPSS 0.07%
- Veröffentlicht 29.11.2024 10:15:10
- Zuletzt bearbeitet 03.12.2024 20:01:52
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.
CVE-2024-38863
- EPSS 0.2%
- Veröffentlicht 14.10.2024 08:15:02
- Zuletzt bearbeitet 03.12.2024 16:47:15
Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.
CVE-2024-38862
- EPSS 0.15%
- Veröffentlicht 14.10.2024 08:15:02
- Zuletzt bearbeitet 03.12.2024 16:56:19
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to be written to audit log files accessible to adminis...
CVE-2024-6747
- EPSS 0.42%
- Veröffentlicht 10.10.2024 08:15:03
- Zuletzt bearbeitet 15.10.2024 13:22:17
Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data
CVE-2024-8606
- EPSS 0.1%
- Veröffentlicht 23.09.2024 07:15:02
- Zuletzt bearbeitet 30.09.2024 15:32:34
Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication
CVE-2024-38860
- EPSS 1.21%
- Veröffentlicht 17.09.2024 14:15:17
- Zuletzt bearbeitet 11.12.2024 03:01:28
Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.
CVE-2024-6572
- EPSS 0.27%
- Veröffentlicht 09.09.2024 10:15:01
- Zuletzt bearbeitet 25.08.2025 14:53:24
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic
CVE-2024-38858
- EPSS 1.23%
- Veröffentlicht 02.09.2024 12:15:19
- Zuletzt bearbeitet 04.09.2024 14:39:10
Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.