Tribe29 records
18 published records for vendor tribe29.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 61.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-140 Improper Neutralization of Delimiters1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-276 Incorrect Default Permissions1
- CWE-285 Improper Authorization1
- CWE-303 Incorrect Implementation of Authentication Algorithm1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2021-40905Proof of concept | The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" filecheckmk · checkmk · CWE-434 | High8.8 | — | 3.0% | Mar 25, 2022 |
35Monitor | CVE-2023-31209No exploit | Command injection via active checks and REST APIcheckmk · checkmk · CWE-78 | High8.8 | — | 1.1% | Aug 10, 2023 |
35Monitor | CVE-2023-31208No exploit | Livestatus command injection in RestAPIcheckmk · checkmk · CWE-140 | High8.8 | — | 1.0% | May 17, 2023 |
35Monitor | CVE-2023-22294No exploit | Privilege escalation in Checkmk Appliancetribe29 · checkmk · CWE-732 | High8.8 | — | 0.7% | Apr 18, 2023 |
32Monitor | CVE-2023-0284No exploit | Improper validation of LDAP user IDscheckmk · checkmk · CWE-20 | High8.1 | — | 0.9% | Jan 26, 2023 |
31Monitor | CVE-2023-6735No exploit | Privilege escalation in mk_tsmcheckmk · checkmk · CWE-95 | High7.8 | — | 0.3% | Jan 12, 2024 |
31Monitor | CVE-2022-33912No exploit | A permission issue affects users that deployed the shipped version of the Checkmk Debian package.checkmk · checkmk · CWE-276 | High7.8 | — | 0.2% | Jun 17, 2022 |
31Monitor | CVE-2023-6740No exploit | Privilege escalation in jar_signaturecheckmk · checkmk · CWE-427 | High7.8 | — | 0.2% | Jan 12, 2024 |
30Monitor | CVE-2023-22318No exploit | Denial of service against webconftribe29 · checkmk appliance firmware · CWE-412 | High7.5 | — | 0.5% | May 15, 2023 |
26Monitor | CVE-2023-31211No exploit | Disabled automation users could still authenticatecheckmk · checkmk · CWE-303 | Medium6.5 | — | 0.5% | Jan 12, 2024 |
26Monitor | CVE-2022-31258No exploit | In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.checkmk · checkmk · CWE-59 | Medium6.7 | — | 0.4% | May 20, 2022 |
24Monitor | CVE-2021-40906Proof of concept | CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated checkmk · checkmk · CWE-79 | Medium6.1 | — | 1.0% | Mar 25, 2022 |
24Monitor | CVE-2023-22309No exploit | Reflected Cross Site Scripting (XSS)tribe29 · checkmk appliance firmware · CWE-80 | Medium6.1 | — | 0.4% | Apr 20, 2023 |
22Monitor | CVE-2023-6287No exploit | Backup password in GET parametertribe29 · checkmk appliance firmware · CWE-598 | Medium5.5 | — | 0.2% | Nov 27, 2023 |
22Monitor | CVE-2023-22307No exploit | Site-Passwords in GET parameterstribe29 · checkmk appliance firmware · CWE-200 | Medium5.5 | — | 0.2% | Apr 18, 2023 |
21Monitor | CVE-2023-1768No exploit | Symmetric agent data encryption fails silentlycheckmk · checkmk · CWE-446 | Medium5.3 | — | 0.9% | Apr 4, 2023 |
21Monitor | CVE-2023-22288No exploit | Email HTML Injectioncheckmk · checkmk · CWE-138 | Medium5.4 | — | 0.4% | Mar 20, 2023 |
17Monitor | CVE-2023-22348No exploit | Reading host_configs does not honour contact groupscheckmk · checkmk · CWE-285 | Medium4.3 | — | 0.6% | May 17, 2023 |
- CVE-2021-4090536Monitor
The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" file
HighCVSS 8.8Proof of conceptEPSS 3%checkmk · checkmkMar 25, 2022
- CVE-2023-3120935Monitor
Command injection via active checks and REST API
HighCVSS 8.8No exploitEPSS 1%checkmk · checkmkAug 10, 2023
- CVE-2023-3120835Monitor
Livestatus command injection in RestAPI
HighCVSS 8.8No exploitEPSS 1%checkmk · checkmkMay 17, 2023
- CVE-2023-2229435Monitor
Privilege escalation in Checkmk Appliance
HighCVSS 8.8No exploitEPSS 1%tribe29 · checkmkApr 18, 2023
- CVE-2023-028432Monitor
Improper validation of LDAP user IDs
HighCVSS 8.1No exploitEPSS 1%checkmk · checkmkJan 26, 2023
- CVE-2023-673531Monitor
Privilege escalation in mk_tsm
HighCVSS 7.8No exploitEPSS 0%checkmk · checkmkJan 12, 2024
- CVE-2022-3391231Monitor
A permission issue affects users that deployed the shipped version of the Checkmk Debian package.
HighCVSS 7.8No exploitEPSS 0%checkmk · checkmkJun 17, 2022
- CVE-2023-674031Monitor
Privilege escalation in jar_signature
HighCVSS 7.8No exploitEPSS 0%checkmk · checkmkJan 12, 2024
- CVE-2023-2231830Monitor
Denial of service against webconf
HighCVSS 7.5No exploitEPSS 1%tribe29 · checkmk appliance firmwareMay 15, 2023
- CVE-2023-3121126Monitor
Disabled automation users could still authenticate
MediumCVSS 6.5No exploitEPSS 1%checkmk · checkmkJan 12, 2024
- CVE-2022-3125826Monitor
In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.
MediumCVSS 6.7No exploitEPSS 0%checkmk · checkmkMay 20, 2022
- CVE-2021-4090624Monitor
CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated
MediumCVSS 6.1Proof of conceptEPSS 1%checkmk · checkmkMar 25, 2022
- CVE-2023-2230924Monitor
Reflected Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%tribe29 · checkmk appliance firmwareApr 20, 2023
- CVE-2023-628722Monitor
Backup password in GET parameter
MediumCVSS 5.5No exploitEPSS 0%tribe29 · checkmk appliance firmwareNov 27, 2023
- CVE-2023-2230722Monitor
Site-Passwords in GET parameters
MediumCVSS 5.5No exploitEPSS 0%tribe29 · checkmk appliance firmwareApr 18, 2023
- CVE-2023-176821Monitor
Symmetric agent data encryption fails silently
MediumCVSS 5.3No exploitEPSS 1%checkmk · checkmkApr 4, 2023
- CVE-2023-2228821Monitor
Email HTML Injection
MediumCVSS 5.4No exploitEPSS 0%checkmk · checkmkMar 20, 2023
- CVE-2023-2234817Monitor
Reading host_configs does not honour contact groups
MediumCVSS 4.3No exploitEPSS 1%checkmk · checkmkMay 17, 2023