2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2021-40906" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2022-03-25T23:15:08.287" ,
2024-11-23 15:12:23 +00:00
"lastModified" : "2024-11-21T06:25:04.797" ,
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication."
} ,
{
"lang" : "es" ,
"value" : "El software CheckMK Raw Edition (versiones 1.5.0 a 1.6.0) no sanea la entrada de un par\u00e1metro de servicio web que est\u00e1 en una zona no autenticada. Este ataque de tipo XSS reflejado permite a un atacante abrir una puerta trasera en el dispositivo con contenido HTML e interpretado por el navegador (como JavaScript u otros scripts del lado del cliente) o robar las cookies de sesi\u00f3n de un usuario que se haya autenticado previamente por medio de un ataque de tipo man in the middle. Una explotaci\u00f3n con \u00e9xito requiere el acceso al recurso del servicio web sin autenticaci\u00f3n"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" ,
2024-11-23 15:12:23 +00:00
"baseScore" : 6.1 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 2.7
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N" ,
2024-11-23 15:12:23 +00:00
"baseScore" : 4.3 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "PARTIAL" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*" ,
2023-04-24 12:24:31 +02:00
"versionStartIncluding" : "1.5.0" ,
"versionEndExcluding" : "1.6.0" ,
2024-07-23 20:03:11 +00:00
"matchCriteriaId" : "52593590-1B3F-497C-B1CA-B2395CC7F5FD"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "5D63367A-3B90-462E-B6AD-1CB5721FD45E"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:b1:*:*:*:*:*:*" ,
"matchCriteriaId" : "E5E2E954-B3C3-4CC0-B2C8-0E2BEEC93016"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:b10:*:*:*:*:*:*" ,
"matchCriteriaId" : "1638594A-84F1-44F6-BB30-D4CC73ECDA38"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:b12:*:*:*:*:*:*" ,
"matchCriteriaId" : "7B2757BF-E3B7-487A-8929-0208D3B0D3CE"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:b3:*:*:*:*:*:*" ,
"matchCriteriaId" : "F01E79D2-EFA4-4A7E-A286-3E86F52B429D"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:b4:*:*:*:*:*:*" ,
"matchCriteriaId" : "D12A6070-0542-4293-AE13-85D4E81E1672"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:b5:*:*:*:*:*:*" ,
"matchCriteriaId" : "6AF633FE-DE7C-4548-9ED2-880E915FC33C"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:b9:*:*:*:*:*:*" ,
"matchCriteriaId" : "F15190EF-E3F5-4AD1-B748-C0E63C8CB741"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p1:*:*:*:*:*:*" ,
"matchCriteriaId" : "30F84B89-7EC6-44E6-A164-4C170379D55C"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p10:*:*:*:*:*:*" ,
"matchCriteriaId" : "DDA94D2F-F27C-4DF6-84AE-8ED1BBC7F61E"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p11:*:*:*:*:*:*" ,
"matchCriteriaId" : "71CF8EFD-17F6-4D9A-961A-4B949A6C8B61"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p12:*:*:*:*:*:*" ,
"matchCriteriaId" : "B04DC2A8-CF05-4FB2-AE2F-AE07943B998D"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p13:*:*:*:*:*:*" ,
"matchCriteriaId" : "1F3BECA6-983C-436E-A635-4E1FB9080E56"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p14:*:*:*:*:*:*" ,
"matchCriteriaId" : "51A9A2B4-3693-490A-94E2-64E1DB795646"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p15:*:*:*:*:*:*" ,
"matchCriteriaId" : "C14AB385-8A9F-46FA-A1C5-4A4A45C1B7F5"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p16:*:*:*:*:*:*" ,
"matchCriteriaId" : "EC41CC5F-F088-4E65-B076-35665F0F6C7E"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p19:*:*:*:*:*:*" ,
"matchCriteriaId" : "EC636B76-B050-4B73-A524-21862B020797"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p2:*:*:*:*:*:*" ,
"matchCriteriaId" : "D49B1D63-8FDD-45FD-99F0-AA9E4FBCCB00"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p20:*:*:*:*:*:*" ,
"matchCriteriaId" : "8AFA4AF4-8395-4BBB-BA78-7116AC1DCDE7"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p21:*:*:*:*:*:*" ,
"matchCriteriaId" : "5565C1C5-5C23-4449-AB87-49A304382387"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p22:*:*:*:*:*:*" ,
"matchCriteriaId" : "78320525-F346-4419-81E3-4A47BD17C808"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p23:*:*:*:*:*:*" ,
"matchCriteriaId" : "EA91018D-DA38-4026-9F47-383F16C85031"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p24:*:*:*:*:*:*" ,
"matchCriteriaId" : "E8DBEF67-A9AE-46D5-89D0-076CDB1AA06A"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p25:*:*:*:*:*:*" ,
"matchCriteriaId" : "63E87316-1CB2-4CF4-B379-4284C8C39053"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p3:*:*:*:*:*:*" ,
"matchCriteriaId" : "9CCE5845-1B77-4E97-B508-41400F4E1F31"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p4:*:*:*:*:*:*" ,
"matchCriteriaId" : "3FCED94F-7683-40FE-B511-F1F49CDD1F73"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p5:*:*:*:*:*:*" ,
"matchCriteriaId" : "0C4E70EC-3D46-40CE-AD59-597EFD721014"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p6:*:*:*:*:*:*" ,
"matchCriteriaId" : "12E695A8-9A1E-4D7A-AB3B-AAC2CF777773"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p7:*:*:*:*:*:*" ,
"matchCriteriaId" : "653632A8-E700-404A-ADB2-B3A50253ECB0"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p8:*:*:*:*:*:*" ,
"matchCriteriaId" : "60733789-DDA3-4819-A9F1-70B76AC715CB"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
2024-07-23 20:03:11 +00:00
"criteria" : "cpe:2.3:a:checkmk:checkmk:1.6.0:p9:*:*:*:*:*:*" ,
"matchCriteriaId" : "D90DBA66-EF97-4CE9-AD4C-3A82F70D2250"
2023-04-24 12:24:31 +02:00
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0b10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3EE29788-9815-47C5-88CC-039E82348482"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0b11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AF943CDA-131A-4951-9281-C0F7711C511B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0p10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2FA770FD-D758-4590-9A6E-5A87E137C53E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0p17:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6786541D-CB3B-432D-8D0F-05178237FE4C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tribe29:checkmk:1.6.0p18:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E668FDEE-6503-4FF5-BA24-DD84180CB38A"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://checkmk.com" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Product"
]
} ,
{
"url" : "https://github.com/Edgarloyola/CVE-2021-40906" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
2024-11-23 15:12:23 +00:00
} ,
{
"url" : "http://checkmk.com" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Product"
]
} ,
{
"url" : "https://github.com/Edgarloyola/CVE-2021-40906" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}