CVE-2023-6735

HIGH

Checkmk < 2.0.0 - Improper Privilege Management

Title source: rule
STIX 2.1

Description

Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Scores

CVSS v3 8.8
EPSS 0.0007
EPSS Percentile 20.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269 CWE-95
Status published
Products (2)
checkmk/checkmk 2.0.0 b1 (47 CPE variants)
checkmk/checkmk 2.1.0 (3 CPE variants)
Published Jan 12, 2024
Tracked Since Feb 18, 2026