CVE-2024-6572
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'
Severity Score
6.3
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic
La verificación incorrecta de la clave del host en la verificación activa 'Check SFTP Service' y el agente especial 'VNX quotas and filesystem' en Checkmk anterior a Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 y 2.0.0 (EOL) permite a los atacantes intermediarios interceptar el tráfico
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-07-08 CVE Reserved
- 2024-09-09 CVE Published
- 2024-09-09 CVE Updated
- 2024-09-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-322: Key Exchange without Entity Authentication
CAPEC
- CAPEC-94: Adversary in the Middle (AiTM)
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.3.0 < 2.3.0p15 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.3.0 < 2.3.0p15" | en |
Affected
| ||||||
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.2.0 < 2.2.0p33 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.2.0 < 2.2.0p33" | en |
Affected
| ||||||
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.1.0 < 2.1.0p48 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.1.0 < 2.1.0p48" | en |
Affected
| ||||||
Checkmk GmbH Search vendor "Checkmk GmbH" | Checkmk Search vendor "Checkmk GmbH" for product "Checkmk" | >= 2.0.0 <= 2.0.0p39 Search vendor "Checkmk GmbH" for product "Checkmk" and version " >= 2.0.0 <= 2.0.0p39" | en |
Affected
|