CVE-2024-38861

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Sep 27, 2024
Updated: Dec 20, 2024
CWE ID 295

Summary

CVE-2024-38861 is a vulnerability affecting the Checkmk Exchange plugin used in MikroTik networks. The issue involves improper certificate validation, allowing attackers in man-in-the-middle (MitM) positions to intercept traffic. This security weakness affects MikroTik versions from 2.0.0 through 2.5.5 and from 0.4a_mk through 2.0a. Attackers can exploit this vulnerability to conduct man-in-the-middle attacks, potentially gaining unauthorized access to sensitive information exchanged between affected devices. Mitigations include upgrading to a patched version of the plugin or implementing certificate pinning to prevent the use of compromised certificates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share