CRITICAL🇵🇱 Wersja polska

CVE-2024-8606

CVSS 9.2v4.0pub. 2024-09-23upd. 2024-09-30

Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication

🤖 AI Analysis
How it works

The second factor authentication verification mechanism (CWE-863 — improper authorization) in the RestAPI interface is not properly enforced. An authenticated user possessing valid first-factor credentials (username and password) can make requests to RestAPI bypassing the required 2FA verification step. This means that the additional code or token-based protection is effectively ineffective in the context of API access.

Impact

An attacker possessing stolen or leaked login credentials (username and password) can gain full access to Checkmk RestAPI without needing to pass two-factor verification, leading to takeover of the monitoring system, unauthorized access to sensitive configuration data, and potential modification of monitored infrastructure settings.

Mitigation & patch

Update Checkmk to version 2.3.0p16 or newer (for the 2.3.x branch) or to version 2.2.0p34 or newer (for the 2.2.x branch). Details available in the vendor advisory: https://checkmk.com/werk/16218

Who is affected

Checkmk in versions earlier than 2.3.0p16 and earlier than 2.2.0p34

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Checkmk

    APP
    Checkmk
    2.2.02.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-39666CRITICAL9.3PL ✓same product

Local privilege escalation w Checkmk — eskalacja do root przez manipulację plikami

CVE-2022-46836CRITICAL9.1PL ✓same product

PHP code injection w Checkmk — wstrzyknięcie i wykonanie kodu PHP (RCE)

CVE-2026-7186HIGH8.5same product

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2...

CVE-2026-8833HIGH8.5same product

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p...

CVE-2026-3466HIGH8.5same product

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p...