Lucene search

K
cvelistCheckmkCVELIST:CVE-2023-31210
HistoryDec 13, 2023 - 8:26 a.m.

CVE-2023-31210 Privilege escalation in agent via LD_LIBRARY_PATH

2023-12-1308:26:46
CWE-427
Checkmk
www.cve.org
3
cve-2023-31210
privilege escalation
checkmk 2.2.0p10
injection
malicious libraries

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0

Percentile

9.0%

Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Checkmk",
    "vendor": "Checkmk GmbH",
    "versions": [
      {
        "lessThan": "2.2.0p17",
        "status": "affected",
        "version": "2.2.0p10",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVELIST:CVE-2023-31210