Impact
A crafted sapstartsrv process name fools the mk_sap_hana agent plugin in Checkmk into believing it is monitoring a SAP HANA instance. Since the plugin runs with elevated privileges (RUNAS=agent) and builds a command based on process identifiers, an attacker can supply a malicious process name that causes the plugin to execute arbitrary shell commands as root. This results in a local privilege escalation that allows an unprivileged user to gain full control of the host.
Affected Systems
The vulnerability exists in Checkmk products from Checkmk GmbH. Affected releases include version 2.5.0 through 2.5.0p8, 2.4.0 through 2.4.0p33, 2.3.0 through 2.3.0p48, and the end‑of‑life 2.2.0. Any installation of these releases without a patched mk_sap_hana plugin is susceptible. The vendor explicitly notes that the issue fixed in 2.5.0p9, 2.4.0p34, and 2.3.0p49.
Risk and Exploitability
The CVSS score of 5.2 indicates moderate severity, but the EPSS score is below 1%, suggesting a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attack feasibility requires a local, non‑privileged account and the presence of the mk_sap_hana plugin running with RUNAS=agent. An attacker can create a benign‑looking sapstartsrv process that contains a malicious command sequence, triggering the vulnerable logic and achieving root execution.
OpenCVE Enrichment