Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic
References
History

Mon, 09 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Checkmk
Checkmk checkmk
CPEs cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
Vendors & Products Checkmk
Checkmk checkmk
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Sep 2024 09:45:00 +0000

Type Values Removed Values Added
Description Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic
Title Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'
Weaknesses CWE-322
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published: 2024-09-09T09:39:17.769Z

Updated: 2024-09-09T13:03:22.065Z

Reserved: 2024-07-08T15:50:02.376Z

Link: CVE-2024-6572

cve-icon Vulnrichment

Updated: 2024-09-09T13:03:06.539Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-09T10:15:01.863

Modified: 2024-09-09T13:35:00.847

Link: CVE-2024-6572

cve-icon Redhat

No data.