Impact
The vulnerability arises from improper handling of highly compressed data in Checkmk. An attacker who controls a host registered for push mode can send a tiny zlib‑compressed payload that expands during decompression to an arbitrary size, exhausting the memory of the agent receiver. This resource exhaustion can cause the agent to become unresponsive or crash, resulting in a denial of service. The weakness is classified as CWE-409.
Affected Systems
Checkmk GmbH’s Checkmk product is affected. All versions released before 2.5.0p14, before 2.4.0p37, before 2.3.0p51, and the 2.2.0 release (which is end‑of‑life) are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. An EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, as the attacker must control a host registered for push mode to exploit the flaw. Successful exploitation would result in memory exhaustion of the agent receiver but does not directly compromise data confidentiality or integrity.
OpenCVE Enrichment