Tribe29 kayıtları
tribe29 üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %61,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-140 Improper Neutralization of Delimiters1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-276 Incorrect Default Permissions1
- CWE-285 Improper Authorization1
- CWE-303 Incorrect Implementation of Authentication Algorithm1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2021-40905Kavram kanıtı | The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" filecheckmk · checkmk · CWE-434 | Yüksek8,8 | — | %3,0 | 25 Mar 2022 |
35İzleyin | CVE-2023-31209İstismar yok | Command injection via active checks and REST APIcheckmk · checkmk · CWE-78 | Yüksek8,8 | — | %1,1 | 10 Ağu 2023 |
35İzleyin | CVE-2023-31208İstismar yok | Livestatus command injection in RestAPIcheckmk · checkmk · CWE-140 | Yüksek8,8 | — | %1,0 | 17 May 2023 |
35İzleyin | CVE-2023-22294İstismar yok | Privilege escalation in Checkmk Appliancetribe29 · checkmk · CWE-732 | Yüksek8,8 | — | %0,7 | 18 Nis 2023 |
32İzleyin | CVE-2023-0284İstismar yok | Improper validation of LDAP user IDscheckmk · checkmk · CWE-20 | Yüksek8,1 | — | %0,9 | 26 Oca 2023 |
31İzleyin | CVE-2023-6735İstismar yok | Privilege escalation in mk_tsmcheckmk · checkmk · CWE-95 | Yüksek7,8 | — | %0,3 | 12 Oca 2024 |
31İzleyin | CVE-2022-33912İstismar yok | A permission issue affects users that deployed the shipped version of the Checkmk Debian package.checkmk · checkmk · CWE-276 | Yüksek7,8 | — | %0,2 | 17 Haz 2022 |
31İzleyin | CVE-2023-6740İstismar yok | Privilege escalation in jar_signaturecheckmk · checkmk · CWE-427 | Yüksek7,8 | — | %0,2 | 12 Oca 2024 |
30İzleyin | CVE-2023-22318İstismar yok | Denial of service against webconftribe29 · checkmk appliance firmware · CWE-412 | Yüksek7,5 | — | %0,5 | 15 May 2023 |
26İzleyin | CVE-2023-31211İstismar yok | Disabled automation users could still authenticatecheckmk · checkmk · CWE-303 | Orta6,5 | — | %0,5 | 12 Oca 2024 |
26İzleyin | CVE-2022-31258İstismar yok | In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.checkmk · checkmk · CWE-59 | Orta6,7 | — | %0,4 | 20 May 2022 |
24İzleyin | CVE-2021-40906Kavram kanıtı | CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated checkmk · checkmk · CWE-79 | Orta6,1 | — | %1,0 | 25 Mar 2022 |
24İzleyin | CVE-2023-22309İstismar yok | Reflected Cross Site Scripting (XSS)tribe29 · checkmk appliance firmware · CWE-80 | Orta6,1 | — | %0,4 | 20 Nis 2023 |
22İzleyin | CVE-2023-6287İstismar yok | Backup password in GET parametertribe29 · checkmk appliance firmware · CWE-598 | Orta5,5 | — | %0,2 | 27 Kas 2023 |
22İzleyin | CVE-2023-22307İstismar yok | Site-Passwords in GET parameterstribe29 · checkmk appliance firmware · CWE-200 | Orta5,5 | — | %0,2 | 18 Nis 2023 |
21İzleyin | CVE-2023-1768İstismar yok | Symmetric agent data encryption fails silentlycheckmk · checkmk · CWE-446 | Orta5,3 | — | %0,9 | 4 Nis 2023 |
21İzleyin | CVE-2023-22288İstismar yok | Email HTML Injectioncheckmk · checkmk · CWE-138 | Orta5,4 | — | %0,4 | 20 Mar 2023 |
17İzleyin | CVE-2023-22348İstismar yok | Reading host_configs does not honour contact groupscheckmk · checkmk · CWE-285 | Orta4,3 | — | %0,6 | 17 May 2023 |
- CVE-2021-4090536İzleyin
The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" file
YüksekCVSS 8,8Kavram kanıtıEPSS %3checkmk · checkmk25 Mar 2022
- CVE-2023-3120935İzleyin
Command injection via active checks and REST API
YüksekCVSS 8,8İstismar yokEPSS %1checkmk · checkmk10 Ağu 2023
- CVE-2023-3120835İzleyin
Livestatus command injection in RestAPI
YüksekCVSS 8,8İstismar yokEPSS %1checkmk · checkmk17 May 2023
- CVE-2023-2229435İzleyin
Privilege escalation in Checkmk Appliance
YüksekCVSS 8,8İstismar yokEPSS %1tribe29 · checkmk18 Nis 2023
- CVE-2023-028432İzleyin
Improper validation of LDAP user IDs
YüksekCVSS 8,1İstismar yokEPSS %1checkmk · checkmk26 Oca 2023
- CVE-2023-673531İzleyin
Privilege escalation in mk_tsm
YüksekCVSS 7,8İstismar yokEPSS %0checkmk · checkmk12 Oca 2024
- CVE-2022-3391231İzleyin
A permission issue affects users that deployed the shipped version of the Checkmk Debian package.
YüksekCVSS 7,8İstismar yokEPSS %0checkmk · checkmk17 Haz 2022
- CVE-2023-674031İzleyin
Privilege escalation in jar_signature
YüksekCVSS 7,8İstismar yokEPSS %0checkmk · checkmk12 Oca 2024
- CVE-2023-2231830İzleyin
Denial of service against webconf
YüksekCVSS 7,5İstismar yokEPSS %1tribe29 · checkmk appliance firmware15 May 2023
- CVE-2023-3121126İzleyin
Disabled automation users could still authenticate
OrtaCVSS 6,5İstismar yokEPSS %1checkmk · checkmk12 Oca 2024
- CVE-2022-3125826İzleyin
In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.
OrtaCVSS 6,7İstismar yokEPSS %0checkmk · checkmk20 May 2022
- CVE-2021-4090624İzleyin
CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated
OrtaCVSS 6,1Kavram kanıtıEPSS %1checkmk · checkmk25 Mar 2022
- CVE-2023-2230924İzleyin
Reflected Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %0tribe29 · checkmk appliance firmware20 Nis 2023
- CVE-2023-628722İzleyin
Backup password in GET parameter
OrtaCVSS 5,5İstismar yokEPSS %0tribe29 · checkmk appliance firmware27 Kas 2023
- CVE-2023-2230722İzleyin
Site-Passwords in GET parameters
OrtaCVSS 5,5İstismar yokEPSS %0tribe29 · checkmk appliance firmware18 Nis 2023
- CVE-2023-176821İzleyin
Symmetric agent data encryption fails silently
OrtaCVSS 5,3İstismar yokEPSS %1checkmk · checkmk4 Nis 2023
- CVE-2023-2228821İzleyin
Email HTML Injection
OrtaCVSS 5,4İstismar yokEPSS %0checkmk · checkmk20 Mar 2023
- CVE-2023-2234817İzleyin
Reading host_configs does not honour contact groups
OrtaCVSS 4,3İstismar yokEPSS %1checkmk · checkmk17 May 2023