Disabled automation users could still authenticate
CVE-2023-31211

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
12 January 2024

What is CVE-2023-31211?

A vulnerability exists in Checkmk products, specifically prior to version 2.2.0p18, 2.1.0p38, and 2.0.0p39, which stems from an insufficient authentication flow. This flaw enables an attacker to potentially misuse locked credentials, posing a significant risk for unauthorized access. Organizations utilizing the affected versions should prioritize timely updates to safeguard their systems against exploitation.

Affected Version(s)

Checkmk 2.2.0 < 2.2.0p18

Checkmk 2.1.0 < 2.1.0p38

Checkmk 2.0.0 <= 2.0.0p39

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.