Local File Security Flaw in Checkmk Affects Sensitive Monitoring Data
CVE-2025-64996
4.8MEDIUM
What is CVE-2025-64996?
The mk_inotify plugin in Checkmk, specifically in versions prior to 2.4.0p16 and 2.3.0p41, creates files with incorrect permissions that are both world-readable and writable. This misconfiguration allows any local user on the system to read the output from these plugin files and alter them. As a result, such access can lead to unauthorized viewing or alteration of sensitive monitoring data, posing significant risks to system integrity and data confidentiality.
Affected Version(s)
Checkmk 2.4.0 < 2.4.0p16
Checkmk 2.3.0 < 2.3.0p41
Checkmk 2.2.0
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
