Lucene search

K
cveMitreCVE-2021-40906
HistoryMar 25, 2022 - 11:15 p.m.

CVE-2021-40906

2022-03-2523:15:08
CWE-79
mitre
web.nvd.nist.gov
82
checkmk
raw edition
software
cve-2021-40906
vulnerability
xss
unauthenticated
web service
parameter
browser
session cookies
authentication

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

29.2%

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.

Affected configurations

Nvd
Node
checkmkcheckmkRange1.5.01.6.0
OR
checkmkcheckmkMatch1.6.0-
OR
checkmkcheckmkMatch1.6.0b1
OR
checkmkcheckmkMatch1.6.0b10
OR
checkmkcheckmkMatch1.6.0b12
OR
checkmkcheckmkMatch1.6.0b3
OR
checkmkcheckmkMatch1.6.0b4
OR
checkmkcheckmkMatch1.6.0b5
OR
checkmkcheckmkMatch1.6.0b9
OR
checkmkcheckmkMatch1.6.0p1
OR
checkmkcheckmkMatch1.6.0p10
OR
checkmkcheckmkMatch1.6.0p11
OR
checkmkcheckmkMatch1.6.0p12
OR
checkmkcheckmkMatch1.6.0p13
OR
checkmkcheckmkMatch1.6.0p14
OR
checkmkcheckmkMatch1.6.0p15
OR
checkmkcheckmkMatch1.6.0p16
OR
checkmkcheckmkMatch1.6.0p19
OR
checkmkcheckmkMatch1.6.0p2
OR
checkmkcheckmkMatch1.6.0p20
OR
checkmkcheckmkMatch1.6.0p21
OR
checkmkcheckmkMatch1.6.0p22
OR
checkmkcheckmkMatch1.6.0p23
OR
checkmkcheckmkMatch1.6.0p24
OR
checkmkcheckmkMatch1.6.0p25
OR
checkmkcheckmkMatch1.6.0p3
OR
checkmkcheckmkMatch1.6.0p4
OR
checkmkcheckmkMatch1.6.0p5
OR
checkmkcheckmkMatch1.6.0p6
OR
checkmkcheckmkMatch1.6.0p7
OR
checkmkcheckmkMatch1.6.0p8
OR
checkmkcheckmkMatch1.6.0p9
OR
tribe29checkmkMatch1.6.0b10
OR
tribe29checkmkMatch1.6.0b11
OR
tribe29checkmkMatch1.6.0p10
OR
tribe29checkmkMatch1.6.0p17
OR
tribe29checkmkMatch1.6.0p18
VendorProductVersionCPE
checkmkcheckmk*cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
checkmkcheckmk1.6.0cpe:2.3:a:checkmk:checkmk:1.6.0:-:*:*:*:*:*:*
checkmkcheckmk1.6.0cpe:2.3:a:checkmk:checkmk:1.6.0:b1:*:*:*:*:*:*
checkmkcheckmk1.6.0cpe:2.3:a:checkmk:checkmk:1.6.0:b10:*:*:*:*:*:*
checkmkcheckmk1.6.0cpe:2.3:a:checkmk:checkmk:1.6.0:b12:*:*:*:*:*:*
checkmkcheckmk1.6.0cpe:2.3:a:checkmk:checkmk:1.6.0:b3:*:*:*:*:*:*
checkmkcheckmk1.6.0cpe:2.3:a:checkmk:checkmk:1.6.0:b4:*:*:*:*:*:*
checkmkcheckmk1.6.0cpe:2.3:a:checkmk:checkmk:1.6.0:b5:*:*:*:*:*:*
checkmkcheckmk1.6.0cpe:2.3:a:checkmk:checkmk:1.6.0:b9:*:*:*:*:*:*
checkmkcheckmk1.6.0cpe:2.3:a:checkmk:checkmk:1.6.0:p1:*:*:*:*:*:*
Rows per page:
1-10 of 371

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

29.2%