Lucene search

K
cveCheckmkCVE-2023-31210
HistoryDec 13, 2023 - 9:15 a.m.

CVE-2023-31210

2023-12-1309:15:34
CWE-427
Checkmk
web.nvd.nist.gov
22
cve-2023-31210
checkmk 2.2.0p10
checkmk 2.2.0p16
ld_library_path
injection
malicious libraries
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

9.0%

Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries

Affected configurations

Nvd
Node
checkmkcheckmkMatch2.2.0p10
OR
checkmkcheckmkMatch2.2.0p11
OR
checkmkcheckmkMatch2.2.0p12
OR
checkmkcheckmkMatch2.2.0p13
OR
checkmkcheckmkMatch2.2.0p14
OR
checkmkcheckmkMatch2.2.0p15
OR
checkmkcheckmkMatch2.2.0p16
VendorProductVersionCPE
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p10:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p11:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p12:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p13:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p14:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p15:*:*:*:*:*:*
checkmkcheckmk2.2.0cpe:2.3:a:checkmk:checkmk:2.2.0:p16:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Checkmk",
    "vendor": "Checkmk GmbH",
    "versions": [
      {
        "lessThan": "2.2.0p17",
        "status": "affected",
        "version": "2.2.0p10",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2023-31210