In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://checkmk.com/werk/18570 |
|
History
Tue, 18 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data. | |
| Title | Overly broad file permissions in the mk_inotify plugin allows reading and manipulating the plugin's output | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-732 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Checkmk
Published: 2025-11-18T15:10:53.398Z
Updated: 2025-11-18T21:23:15.114Z
Reserved: 2025-11-12T09:16:24.091Z
Link: CVE-2025-64996
Updated: 2025-11-18T21:22:48.886Z
Status : Awaiting Analysis
Published: 2025-11-18T16:15:46.563
Modified: 2025-11-19T19:14:59.327
Link: CVE-2025-64996
No data.