Lucene search

K
vulnrichmentCheckmkVULNRICHMENT:CVE-2023-23549
HistoryNov 15, 2023 - 11:07 a.m.

CVE-2023-23549 DoS via long hostnames

2023-11-1511:07:28
CWE-1284
Checkmk
github.com
cve-2023-23549
dos
improper input validation
checkmk
ui

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

AI Score

6.5

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial denial of service of the UI via too long hostnames.

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

AI Score

6.5

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-23549