CVE-2024-38862
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Summary
CVE-2024-38862 is a vulnerability affecting Checkmk versions earlier than 2.3.0p18, 2.2.0p35, 2.1.0p48, and 2.0.0p39. This issue allows sensitive information, specifically SNMP and IMPI secrets of host and folder properties, to be written into audit log files. These log files are accessible to administrators, posing a significant risk if an attacker gains unauthorized access to the system. The vulnerability could potentially lead to unauthorized access or data exfiltration. Users are advised to update their Checkmk installations to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Checkmk
Affected Vendors
- Check MK