Impact
The vulnerability is an incorrect authorization check in frozen Business Intelligence aggregations. It allows an authenticated user who normally has restricted view of certain hosts and services to discover the names and existence of those entities. This breach of confidentiality enables the attacker to build a more complete inventory of the environment for later exploits.
Affected Systems
The flaw exists in Checkmk versions prior to 2.5.0p2, prior to 2.4.0p29, prior to 2.3.0p47, and in all 2.2.0 releases. It affects Checkmk as delivered by Checkmk GmbH, including the open‑source Community Edition and Enterprise releases.
Risk and Exploitability
The CVSS score of 2.3 indicates a low overall impact, yet the information collected could assist in reconnaissance. The exploit requires a valid authenticated session; there is no remote code execution or denial of service. EPSS is not available and the issue is not listed in the CISA KEV catalog, suggesting no known exploits and a low probability of widespread exploitation. The likely attack vector is a legitimate user accessing the Checkmk interface, possibly from a trusted network location.
OpenCVE Enrichment