Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-40905


The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session of a user with administrator role. NOTE: the vendor states that this is the intended behavior: admins are supposed to be able to execute code in this manner


Published

2022-03-25T23:15:08.237

Last Modified

2024-11-21T06:25:04.480

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-434
  • Type: Secondary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application checkmk checkmk 2.0.0 Yes
Application tribe29 checkmk < 2.0.0 Yes

References