CVE-2025-65000

MEDIUM

Checkmk <=2.4.0p18, <=2.3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was deployed.

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 16.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-212
Status published
Products (3)
checkmk/checkmk 2.2.0
checkmk/checkmk 2.3.0 (48 CPE variants)
checkmk/checkmk 2.4.0
Published Dec 18, 2025
Tracked Since Feb 18, 2026