CVE 4.8 MEDIUM

Overly broad file permissions in the mk_inotify plugin allows reading and manipulating the plugin’s output_CVE-2025-64996

4.8 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N

Description

In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data.

Basic Information

ID CVE-2025-64996
Source Checkmk
Published Nov 18, 2025 at 15:10
Modified Nov 18, 2025 at 21:23

Affected Product

Vendor Checkmk GmbH
Product Checkmk
Version 2.4.0
Affected Versions Checkmk GmbH Checkmk 2.4.0
Checkmk GmbH Checkmk 2.3.0
Checkmk GmbH Checkmk 2.2.0
Checkmk GmbH Checkmk 2.1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.