CVE-2024-38862

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Oct 14, 2024
Updated: Dec 3, 2024
CWE ID 532

Summary

CVE-2024-38862 is a vulnerability affecting Checkmk versions earlier than 2.3.0p18, 2.2.0p35, 2.1.0p48, and 2.0.0p39. This issue allows sensitive information, specifically SNMP and IMPI secrets of host and folder properties, to be written into audit log files. These log files are accessible to administrators, posing a significant risk if an attacker gains unauthorized access to the system. The vulnerability could potentially lead to unauthorized access or data exfiltration. Users are advised to update their Checkmk installations to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share