Lucene search

K
cveMitreCVE-2014-2329
HistoryAug 31, 2015 - 6:59 p.m.

CVE-2014-2329

2015-08-3118:59:00
CWE-79
mitre
web.nvd.nist.gov
44
cve
2014
2329
cross-site scripting
xss
check_mk
remote authenticated users
arbitrary web script
html
monitored host
logwatch module
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.1

Confidence

High

EPSS

0.001

Percentile

30.0%

Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject arbitrary web script or HTML via the (1) agent string for a check_mk agent, a (2) crafted request to a monitored host, which is not properly handled by the logwatch module, or other unspecified vectors.

Affected configurations

Nvd
Node
check_mk_projectcheck_mkRange≀1.2.2
OR
check_mk_projectcheck_mkRange≀1.2.3
VendorProductVersionCPE
check_mk_projectcheck_mk*cpe:2.3:a:check_mk_project:check_mk:*:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.1

Confidence

High

EPSS

0.001

Percentile

30.0%