{ "id": "CVE-2024-0638", "sourceIdentifier": "security@checkmk.com", "published": "2024-03-22T11:15:46.183", "lastModified": "2024-12-04T17:00:07.247", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges." }, { "lang": "es", "value": "La violaci\u00f3n m\u00ednima de privilegios en los complementos del agente Checkmk mk_oracle, mk_oracle.ps1 y mk_oracle_crs antes de Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 y 2.0.0 (EOL) permite a los usuarios locales escalar privilegios." } ], "metrics": { "cvssMetricV31": [ { "source": "security@checkmk.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" }, "exploitabilityScore": 1.5, "impactScore": 6.0 }, { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" }, "exploitabilityScore": 0.8, "impactScore": 5.9 } ] }, "weaknesses": [ { "source": "security@checkmk.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-272" } ] }, { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*", "versionEndIncluding": "2.0.0", "matchCriteriaId": "C59985CE-68DF-433D-87BD-97EDCA81E039" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:-:*:*:*:*:*:*", "matchCriteriaId": "1AE224D8-742B-4D1F-ABBE-3DDA3EA5C5AD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:b1:*:*:*:*:*:*", "matchCriteriaId": "1E6FCE7B-7ECE-42A4-82C5-12A647B0CCC8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:b2:*:*:*:*:*:*", "matchCriteriaId": "923AA113-D5E7-4F78-88BA-B72EF250F3EA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:b3:*:*:*:*:*:*", "matchCriteriaId": "B1984F57-A313-48AC-B8F9-F352D82824D6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:b4:*:*:*:*:*:*", "matchCriteriaId": "A38DB527-72A6-40B8-B46F-B8E78BFFDB1F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:b5:*:*:*:*:*:*", "matchCriteriaId": "67643E11-91A1-4580-BC4C-574074C862CB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:b6:*:*:*:*:*:*", "matchCriteriaId": "350B7E0F-D234-4D7C-91E4-F35E73579A24" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:b7:*:*:*:*:*:*", "matchCriteriaId": "DE58ACA9-8078-46A7-8487-C06E4E38F372" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:b8:*:*:*:*:*:*", "matchCriteriaId": "B3D8CF4D-E1F8-4D8D-A8A9-1783CAC869E4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:b9:*:*:*:*:*:*", "matchCriteriaId": "58B0B051-7D3C-4EC7-96B0-38A1CC108D61" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p1:*:*:*:*:*:*", "matchCriteriaId": "B783A741-AAF2-43EE-8272-9239133A01E8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p10:*:*:*:*:*:*", "matchCriteriaId": "A5F275A3-A99E-40E1-BD77-694FA568541F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p11:*:*:*:*:*:*", "matchCriteriaId": "3A44BF1A-5BE0-4412-B51D-055445758B61" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p12:*:*:*:*:*:*", "matchCriteriaId": "A31BAE94-9096-4320-AC19-AA204E8EC08D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p13:*:*:*:*:*:*", "matchCriteriaId": "1B0784EA-98E8-4490-B97B-894F188A223D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p14:*:*:*:*:*:*", "matchCriteriaId": "A56A901F-1040-4DB9-9BE3-FE1999C514CA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p15:*:*:*:*:*:*", "matchCriteriaId": "58A904FC-C015-469D-8502-E678D5FDBD06" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p16:*:*:*:*:*:*", "matchCriteriaId": "1B5D109C-60AA-4FA4-9B10-2191AAF109F2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p17:*:*:*:*:*:*", "matchCriteriaId": "37297866-24BB-4044-8744-EC0A8C29F152" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p18:*:*:*:*:*:*", "matchCriteriaId": "F9D4A171-CCB3-43B8-8B70-78610423E7C0" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p19:*:*:*:*:*:*", "matchCriteriaId": "5E1145FF-426D-407C-9F4B-EF773BD191EC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p2:*:*:*:*:*:*", "matchCriteriaId": "4DA8F776-A724-48FC-B7EF-13788BC69753" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p20:*:*:*:*:*:*", "matchCriteriaId": "46F42A22-99F2-4DF5-9B00-3123396F87AC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p21:*:*:*:*:*:*", "matchCriteriaId": "1C59D4D3-D526-4E6B-B3AA-FE485D030190" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p22:*:*:*:*:*:*", "matchCriteriaId": "65E5CAE6-DC8B-47B3-84A0-D79B0C33EB45" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p23:*:*:*:*:*:*", "matchCriteriaId": "8B9E0D89-79E2-476A-8A3E-8443316BC310" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p24:*:*:*:*:*:*", "matchCriteriaId": "38EA0591-C30B-4102-8A06-1B922FD3A0C7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p25:*:*:*:*:*:*", "matchCriteriaId": "5E9AF0D3-8DD6-4EC7-BB33-54401D4025FC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p26:*:*:*:*:*:*", "matchCriteriaId": "983604CC-DD2C-42A9-8B9D-A9A261CE8BA6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p27:*:*:*:*:*:*", "matchCriteriaId": "224960F7-695C-415B-B991-E8C01859AA80" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p28:*:*:*:*:*:*", "matchCriteriaId": "1F6D86E4-738B-4ADA-858E-C12CCED9FAAA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p29:*:*:*:*:*:*", "matchCriteriaId": "BD8EBF09-9B70-4972-85B1-82F41488BE3F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p3:*:*:*:*:*:*", "matchCriteriaId": "076463AA-195F-4CD6-861B-72FE1C8A407F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p30:*:*:*:*:*:*", "matchCriteriaId": "009D2C7B-39B8-400F-80A5-06D56319232C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p31:*:*:*:*:*:*", "matchCriteriaId": "3D5AEB8D-772E-401F-975C-61BDD30B481E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p32:*:*:*:*:*:*", "matchCriteriaId": "2ECAB6C5-518C-4CA4-8B2B-D51115612A8B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p33:*:*:*:*:*:*", "matchCriteriaId": "FECC252C-02AA-41EC-BB84-5C1A6BC0FB8A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p34:*:*:*:*:*:*", "matchCriteriaId": "238324F5-7225-40DD-82E8-52F30F0D3776" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p35:*:*:*:*:*:*", "matchCriteriaId": "4F3C9510-BD43-4F67-9C30-4F82B5D230E8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p36:*:*:*:*:*:*", "matchCriteriaId": "51941654-F6FF-4323-AECA-5D1D84308CD2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p37:*:*:*:*:*:*", "matchCriteriaId": "6E800133-1D28-41D1-8D73-9437D741F83B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p38:*:*:*:*:*:*", "matchCriteriaId": "8A34B28B-2BD9-4F28-9428-8CF7FCEAD7C3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p39:*:*:*:*:*:*", "matchCriteriaId": "D3FC491E-DE27-4C8F-B699-DB5260935D51" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p4:*:*:*:*:*:*", "matchCriteriaId": "63043834-98E5-47C2-91F1-41B98270ABCA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p40:*:*:*:*:*:*", "matchCriteriaId": "0BE2C8FE-20CC-4B7E-B27B-54C873DC7530" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p5:*:*:*:*:*:*", "matchCriteriaId": "FCF745D0-2EA6-4414-90BC-99D3ED08BB01" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p6:*:*:*:*:*:*", "matchCriteriaId": "4823087F-D7FA-4594-8FD3-412DE5EA1F02" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p7:*:*:*:*:*:*", "matchCriteriaId": "6429F9CE-D477-4CFF-B6E0-4BF11B61ED0E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p8:*:*:*:*:*:*", "matchCriteriaId": "A50C58F9-94ED-4D85-8331-2D81F8E0760A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.1.0:p9:*:*:*:*:*:*", "matchCriteriaId": "9A6AC0BD-FB65-4FAA-B344-66F87F16F8B3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:-:*:*:*:*:*:*", "matchCriteriaId": "C66704F1-0B5E-4B43-8748-987022F378F8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:b1:*:*:*:*:*:*", "matchCriteriaId": "B068974F-6F67-4CBB-B567-FCED86E28F22" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:b2:*:*:*:*:*:*", "matchCriteriaId": "EA70F36A-EEF6-48DC-B15E-055D0DE8A052" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:b3:*:*:*:*:*:*", "matchCriteriaId": "B2017F38-38DB-4E96-B34F-160BC731CBBE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:b4:*:*:*:*:*:*", "matchCriteriaId": "0949F399-371B-409C-AF9F-32690D881440" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:b5:*:*:*:*:*:*", "matchCriteriaId": "42E1E31A-B5CC-45F2-A2E5-3EEF735499BA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:b6:*:*:*:*:*:*", "matchCriteriaId": "4B364FCA-500C-458E-B997-82CD0B1D24F9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:b7:*:*:*:*:*:*", "matchCriteriaId": "0B32E657-917B-482B-B6A4-3D3746992A4F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:b8:*:*:*:*:*:*", "matchCriteriaId": "2119C732-E024-4DA6-8E47-9E08E5E12602" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:i1:*:*:*:*:*:*", "matchCriteriaId": "4F0B99A8-A124-43BD-B8AA-EECC9112346F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p1:*:*:*:*:*:*", "matchCriteriaId": "3FB7221E-BE9F-4529-8E07-8AD547FA3208" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p10:*:*:*:*:*:*", "matchCriteriaId": "30A074AD-9499-46E3-AB67-D6CEE3AA01C3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p11:*:*:*:*:*:*", "matchCriteriaId": "A8BD0240-A22B-4273-BD47-C35A8C12E127" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p12:*:*:*:*:*:*", "matchCriteriaId": "DAA5680F-1DD0-48AA-BB7F-15B27365F0FA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p13:*:*:*:*:*:*", "matchCriteriaId": "BC2F31CA-D4EB-44E6-9A09-5255D33F4A88" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p14:*:*:*:*:*:*", "matchCriteriaId": "CD80BD69-20C6-4E17-B165-98689179A5A1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p15:*:*:*:*:*:*", "matchCriteriaId": "B044D43B-0233-4A0D-A356-B9F9324E2777" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p16:*:*:*:*:*:*", "matchCriteriaId": "7DE79896-EBE5-42F2-A126-2A871BBA1071" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p17:*:*:*:*:*:*", "matchCriteriaId": "51A44E69-EEA1-4B01-B7B3-5BF7B39819E3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p18:*:*:*:*:*:*", "matchCriteriaId": "BCB65AEB-CF52-410B-92B1-2DCFB914FFA4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p19:*:*:*:*:*:*", "matchCriteriaId": "B7E17FA6-9011-489C-9FA9-368CA2D86FAE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p2:*:*:*:*:*:*", "matchCriteriaId": "7BCEB6FF-668F-4313-9264-0BF021AFC45F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p20:*:*:*:*:*:*", "matchCriteriaId": "F8B27218-A4FF-47BE-B578-6DB704478921" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p21:*:*:*:*:*:*", "matchCriteriaId": "8735357F-16A7-4408-9DDD-1C6796BADBE9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p22:*:*:*:*:*:*", "matchCriteriaId": "4505098C-0A2B-481E-A3DF-D6DF8EFA4DE7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p23:*:*:*:*:*:*", "matchCriteriaId": "C12AFCCF-014E-4EEB-8F04-F1ACE182BA98" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p3:*:*:*:*:*:*", "matchCriteriaId": "E2342E2D-58B0-43E7-8C01-DF4678520F39" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p4:*:*:*:*:*:*", "matchCriteriaId": "1871B646-CA69-477F-B113-B901AC7B3934" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p5:*:*:*:*:*:*", "matchCriteriaId": "EEC65A72-CAE1-4E28-83EF-7ECAFE921BB6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p6:*:*:*:*:*:*", "matchCriteriaId": "D8FDECBC-8213-495F-A932-C4310F7C1F87" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p7:*:*:*:*:*:*", "matchCriteriaId": "CB49BC95-6AA8-4F53-A3D6-E199BF756AAF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p8:*:*:*:*:*:*", "matchCriteriaId": "050B6617-8FD4-47A6-BE4A-A52503A65812" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.2.0:p9:*:*:*:*:*:*", "matchCriteriaId": "4CA0FEC5-7036-47AF-A341-873B6C324B58" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.3.0:b1:*:*:*:*:*:*", "matchCriteriaId": "1A020A77-7D84-4557-9B0B-D74A89BC1538" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.3.0:b2:*:*:*:*:*:*", "matchCriteriaId": "D9770554-978B-4552-9E0E-CD6B6675243C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:checkmk:checkmk:2.3.0:b3:*:*:*:*:*:*", "matchCriteriaId": "1883D2F4-CB96-4DDE-87E8-D1990A3FA092" } ] } ] } ], "references": [ { "url": "https://checkmk.com/werk/16232", "source": "security@checkmk.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://checkmk.com/werk/16232", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] } ] }