CVE-2024-28826
Unrestricted upload and download paths in check_sftp
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.
La restricción inadecuada de las rutas de carga y descarga locales en check_sftp en Checkmk anterior a 2.3.0p4, 2.2.0p27, 2.1.0p44 y en Checkmk 2.0.0 (EOL) permite a atacantes con permisos suficientes configurar la verificación para leer y escribir archivos locales en el servidor del sitio Checkmk.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-03-11 CVE Reserved
- 2024-05-29 CVE Published
- 2024-05-30 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-73: External Control of File Name or Path
CAPEC
- CAPEC-212: Functionality Misuse
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.3.0 < 2.3.0p4 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.3.0 < 2.3.0p4" | en |
Affected
| ||||||
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.2.0 < 2.2.0p27 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.2.0 < 2.2.0p27" | en |
Affected
| ||||||
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.1.0 < 2.1.0p44 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.1.0 < 2.1.0p44" | en |
Affected
| ||||||
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.0.0 <= 2.0.0p39 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.0.0 <= 2.0.0p39" | en |
Affected
|