checkmk.com
https://checkmk.com/werk/17148 CVE-2024-6572
MEDIUM
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'
Record summary
CVE-2024-6572 has a selected CVSS score of 6.3 (medium).
Description
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 9, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 2.3.0 to < 2.3.0p15 | affected |
| 2.2.0 to < 2.2.0p33 | affected | ||
| 2.1.0 to < 2.1.0p48 | affected | ||
| 2.0.0 to ≤ 2.0.0p39 | affected | ||
checkmkBrowse checkmk / checkmkDefault status: unknown | CVE List | 2.3.0 to < 2.3.0p15 | affected |
| 2.2.0 to < 2.2.0p33 | affected | ||
| 2.1.0 to < 2.1.0p48 | affected | ||
| 2.0.0 to ≤ 2.0.0p39 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6572