Local Users Abuse Privilege Escalation Vulnerability in Checkmk Agent Plugin
CVE-2024-28829

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
20 August 2024

What is CVE-2024-28829?

The mk_informix Checkmk agent plugin prior to versions 2.3.0p12, 2.2.0p32, 2.1.0p47, and 2.0.0 (which is end-of-life) contains a vulnerability that allows local users to escalate their privileges. This issue arises from a least privilege violation and the reliance on untrusted inputs, presenting significant security risks to systems utilizing these affected versions. It is crucial for users and administrators to assess their environments and take necessary remediation steps to mitigate potential exploitation of this vulnerability.

Affected Version(s)

Checkmk 2.3.0 < 2.3.0p12

Checkmk 2.2.0 < 2.2.0p32

Checkmk 2.1.0 < 2.1.0p47

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.