Disabled automation users could still authenticate
CVE-2023-31211
8.8HIGH
What is CVE-2023-31211?
A vulnerability exists in Checkmk products, specifically prior to version 2.2.0p18, 2.1.0p38, and 2.0.0p39, which stems from an insufficient authentication flow. This flaw enables an attacker to potentially misuse locked credentials, posing a significant risk for unauthorized access. Organizations utilizing the affected versions should prioritize timely updates to safeguard their systems against exploitation.
Affected Version(s)
Checkmk 2.2.0 < 2.2.0p18
Checkmk 2.1.0 < 2.1.0p38
Checkmk 2.0.0 <= 2.0.0p39
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
