Skip to content
supertechspain.com
Menu
  • Gadgets
  • Graphic Design
  • Network
  • Programming
  • Software
  • Technology News
Menu

Multiple Vulnerabilities Reported in Checkmk IT Infrastructure Monitoring Software

Posted on 04/11/2022
Checkmk IT Infrastructure Monitoring Software

Multiple vulnerabilities have been disclosed in Checkmk IT Infrastructure monitoring software that could be chained together by an unauthenticated, remote attacker to fully take over affected servers.

“These vulnerabilities can be chained together by an unauthenticated, remote attacker to gain code execution on the server running Checkmk version 2.1.0p10 and lower,” SonarSource researcher Stefan Schiller said in a technical analysis.

Checkmk’s open source edition of the monitoring tool is based on Nagios Core and offers integrations with NagVis for the visualization and generation of topological maps of infrastructures, servers, ports, and processes.

According to its Munich-based developer tribe29 GmbH, its Enterprise and Raw editions are used by over 2,000 customers, including Airbus, Adobe, NASA, Siemens, Vodafone, and others.

Checkmk IT Infrastructure Monitoring Software

The four vulnerabilities, which consist of two Critical and two Medium severity bugs, are as follows –

While these drawbacks on their own have a limited impact, an adversary can chain the issues, starting with the SSRF flaw to access an endpoint only reachable from localhost, using it to bypass authentication and read a configuration file, ultimately gaining access to the Checkmk GUI .

CyberSecurity

“This access can further be turned into remote code execution by exploiting a Code Injection vulnerability in a Checkmk GUI subcomponent called watolib, which generates a file named auth.php required for the NagVis integration,” Schiller explained.

Following responsible disclosure on August 22, 2022, the four vulnerabilities have been patched in Checkmk version 2.1.0p12 released on September 15, 2022.

The findings follow the discovery of multiple flaws in other monitoring solutions like Zabbix and Icinga since the start of the year, which could have been exploited to compromise the servers by running arbitrary code.

Recent Posts

  • CNN to end HLN’s live programming as part of the network’s big job cuts
  • German extends energy subsidy plan for consumers, companies
  • Fortinet Launches Managed Cloud-Native Firewall Service to Simplify Network Security … | News
  • Gundam Manga Illustrator Recalls an Earlier Time When Sexism Prevented a Female Protagonist – Interest
  • New WWE Programming Returning to A&E in February

Archives

  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022

Categories

  • Gadgets
  • Graphic Design
  • Network
  • Programming
  • Software

About Us

  • Contact Us
  • Advertise Here
  • Disclosure Policy
  • Sitemap

Partner Links

Partner Links

Support Links

©2023 supertechspain.com | Design: Newspaperly WordPress Theme