CVE-2017-14955
Check_MK 1.2.8p25 - Information Disclosure
Severity Score
5.9
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
Check_MK en versiones anteriores a la 1.2.8p26 gestiona de manera incorrecta determinados errores en la característica de guardado de intentos fallidos de inicio de sesión por culpa de una condición de carrera que permite que los atacantes remotos obtengan información sensible de usuarios leyendo un informe de cierre inesperado de la interfaz gráfica de usuario.
Check_mk versions 1.2.8p25 and below suffer from a save_users() race condition that leads to sensitive information disclosure.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-10-01 CVE Reserved
- 2017-10-01 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-11-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://mathias-kettner.com/check_mk_werks.php?edition_id=raw&branch=1.2.8 | Release Notes | |
https://mathias-kettner.de/check_mk_werks.php?werk_id=5208&HTML=yes | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/43021 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Checkmk Search vendor "Checkmk" | Checkmk Search vendor "Checkmk" for product "Checkmk" | 1.2.3 Search vendor "Checkmk" for product "Checkmk" and version "1.2.3" | i6 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.3 Search vendor "Tribe29" for product "Checkmk" and version "1.2.3" | i7 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.4 Search vendor "Tribe29" for product "Checkmk" and version "1.2.4" | b1 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.5 Search vendor "Tribe29" for product "Checkmk" and version "1.2.5" | i1 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.5 Search vendor "Tribe29" for product "Checkmk" and version "1.2.5" | i2 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.5 Search vendor "Tribe29" for product "Checkmk" and version "1.2.5" | i3 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.5 Search vendor "Tribe29" for product "Checkmk" and version "1.2.5" | i4 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.5 Search vendor "Tribe29" for product "Checkmk" and version "1.2.5" | i5 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.5 Search vendor "Tribe29" for product "Checkmk" and version "1.2.5" | i6 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.6 Search vendor "Tribe29" for product "Checkmk" and version "1.2.6" | b1 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.6 Search vendor "Tribe29" for product "Checkmk" and version "1.2.6" | b2 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.6 Search vendor "Tribe29" for product "Checkmk" and version "1.2.6" | p13 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.7 Search vendor "Tribe29" for product "Checkmk" and version "1.2.7" | i1 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.7 Search vendor "Tribe29" for product "Checkmk" and version "1.2.7" | i1p2 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.7 Search vendor "Tribe29" for product "Checkmk" and version "1.2.7" | i2 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.7 Search vendor "Tribe29" for product "Checkmk" and version "1.2.7" | i3 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.7 Search vendor "Tribe29" for product "Checkmk" and version "1.2.7" | i4 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.8 Search vendor "Tribe29" for product "Checkmk" and version "1.2.8" | p18 |
Affected
| ||||||
Tribe29 Search vendor "Tribe29" | Checkmk Search vendor "Tribe29" for product "Checkmk" | 1.2.8 Search vendor "Tribe29" for product "Checkmk" and version "1.2.8" | p25 |
Affected
|