Lucene search

K
cveMitreCVE-2017-14955
HistoryOct 02, 2017 - 1:29 a.m.

CVE-2017-14955

2017-10-0201:29:00
CWE-200
CWE-362
mitre
web.nvd.nist.gov
55
cve-2017-14955
check_mk
security vulnerability
remote attack
gui crash report

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.4

Confidence

High

EPSS

0.015

Percentile

87.0%

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

Affected configurations

Nvd
Node
checkmkcheckmkMatch1.2.3i6
OR
checkmkcheckmkMatch1.2.3i7
OR
checkmkcheckmkMatch1.2.4b1
OR
checkmkcheckmkMatch1.2.5i1
OR
checkmkcheckmkMatch1.2.5i2
OR
checkmkcheckmkMatch1.2.5i3
OR
checkmkcheckmkMatch1.2.5i4
OR
checkmkcheckmkMatch1.2.5i5
OR
checkmkcheckmkMatch1.2.5i6
OR
checkmkcheckmkMatch1.2.6b1
OR
checkmkcheckmkMatch1.2.6b2
OR
checkmkcheckmkMatch1.2.6p13
OR
checkmkcheckmkMatch1.2.7i1
OR
checkmkcheckmkMatch1.2.7i1p2
OR
checkmkcheckmkMatch1.2.7i2
OR
checkmkcheckmkMatch1.2.7i3
OR
checkmkcheckmkMatch1.2.7i4
OR
checkmkcheckmkMatch1.2.8p18
OR
checkmkcheckmkMatch1.2.8p25
VendorProductVersionCPE
checkmkcheckmk1.2.3cpe:2.3:a:checkmk:checkmk:1.2.3:i6:*:*:*:*:*:*
checkmkcheckmk1.2.3cpe:2.3:a:checkmk:checkmk:1.2.3:i7:*:*:*:*:*:*
checkmkcheckmk1.2.4cpe:2.3:a:checkmk:checkmk:1.2.4:b1:*:*:*:*:*:*
checkmkcheckmk1.2.5cpe:2.3:a:checkmk:checkmk:1.2.5:i1:*:*:*:*:*:*
checkmkcheckmk1.2.5cpe:2.3:a:checkmk:checkmk:1.2.5:i2:*:*:*:*:*:*
checkmkcheckmk1.2.5cpe:2.3:a:checkmk:checkmk:1.2.5:i3:*:*:*:*:*:*
checkmkcheckmk1.2.5cpe:2.3:a:checkmk:checkmk:1.2.5:i4:*:*:*:*:*:*
checkmkcheckmk1.2.5cpe:2.3:a:checkmk:checkmk:1.2.5:i5:*:*:*:*:*:*
checkmkcheckmk1.2.5cpe:2.3:a:checkmk:checkmk:1.2.5:i6:*:*:*:*:*:*
checkmkcheckmk1.2.6cpe:2.3:a:checkmk:checkmk:1.2.6:b1:*:*:*:*:*:*
Rows per page:
1-10 of 191

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.4

Confidence

High

EPSS

0.015

Percentile

87.0%