CVE-2020-24908

Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tribe29:checkmk:*:*:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:-:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p1:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p10:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p11:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p12:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p13:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p14:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p15:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p16:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p2:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p3:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p4:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p5:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p6:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p7:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p8:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p9:*:*:*:*:*:*

History

25 Feb 2021, 13:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
CPE cpe:2.3:a:tribe29:checkmk:1.6.0:p12:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p9:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p16:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p13:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p5:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p14:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p2:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:-:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p7:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p4:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:*:*:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p10:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p1:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p15:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p3:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p8:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p6:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.6.0:p11:*:*:*:*:*:*
CWE NVD-CWE-Other
References (MISC) https://compass-security.com/fileadmin/Research/Advisories/2020-05_CSNC-2020-005_Checkmk_Local_Privilege_Escalation.txt - (MISC) https://compass-security.com/fileadmin/Research/Advisories/2020-05_CSNC-2020-005_Checkmk_Local_Privilege_Escalation.txt - Third Party Advisory

19 Feb 2021, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-19 06:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-24908

Mitre link : CVE-2020-24908

CVE.ORG link : CVE-2020-24908


JSON object : View

Products Affected

tribe29

  • checkmk