Insufficient Permission Validation in Checkmk Affects User Data Access
CVE-2025-64997
6.3MEDIUM
What is CVE-2025-64997?
A security vulnerability in Checkmk allows users with low privileges to bypass permission controls and access sensitive agent information through the REST API. This flaw affects versions prior to 2.4.0p17 and 2.3.0p42, risking potential information disclosure that could compromise system integrity. Users are advised to upgrade to the latest versions to mitigate this risk.
Affected Version(s)
Checkmk 2.4.0 < 2.4.0p17
Checkmk 2.3.0 < 2.3.0p42
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
PS Positive Security GmbH
