Impact
The agent receiver component of Checkmk lacks proper authentication checks, which allows an unauthenticated attacker to craft a request that bypasses the mutual TLS client certificate validation by inserting a fixed placeholder identity into the request URL. Although the impact is limited to integrity and availability of the affected endpoints, the attacker can potentially impersonate or gain unauthorized access to the system.
Affected Systems
Vendors and products affected are Checkmk GmbH Checkmk, specifically the Cloud, Ultimate, and Ultimate MT editions running versions prior to 2.5.0p10. These editions expose relay endpoints that can be targeted; editions that do not expose relay endpoints are not affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote HTTP/HTTPS request to the agent receiver’s relay endpoint using a placeholder identity; the attacker does not need prior authentication or credentials. The risk is elevated for environments where the relay endpoints are publicly reachable or where the Cloud, Ultimate, or Ultimate MT editions are deployed without timely patches.
OpenCVE Enrichment