First published: Fri Feb 19 2021(Updated: )
Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tribe29 Checkmk | <1.6.0 | |
Tribe29 Checkmk | =1.6.0 | |
Tribe29 Checkmk | =1.6.0-p1 | |
Tribe29 Checkmk | =1.6.0-p10 | |
Tribe29 Checkmk | =1.6.0-p11 | |
Tribe29 Checkmk | =1.6.0-p12 | |
Tribe29 Checkmk | =1.6.0-p13 | |
Tribe29 Checkmk | =1.6.0-p14 | |
Tribe29 Checkmk | =1.6.0-p15 | |
Tribe29 Checkmk | =1.6.0-p16 | |
Tribe29 Checkmk | =1.6.0-p2 | |
Tribe29 Checkmk | =1.6.0-p3 | |
Tribe29 Checkmk | =1.6.0-p4 | |
Tribe29 Checkmk | =1.6.0-p5 | |
Tribe29 Checkmk | =1.6.0-p6 | |
Tribe29 Checkmk | =1.6.0-p7 | |
Tribe29 Checkmk | =1.6.0-p8 | |
Tribe29 Checkmk | =1.6.0-p9 | |
Checkmk Checkmk | <1.6.0 | |
Checkmk Checkmk | =1.6.0 | |
Checkmk Checkmk | =1.6.0-p1 | |
Checkmk Checkmk | =1.6.0-p10 | |
Checkmk Checkmk | =1.6.0-p11 | |
Checkmk Checkmk | =1.6.0-p12 | |
Checkmk Checkmk | =1.6.0-p13 | |
Checkmk Checkmk | =1.6.0-p14 | |
Checkmk Checkmk | =1.6.0-p15 | |
Checkmk Checkmk | =1.6.0-p16 | |
Checkmk Checkmk | =1.6.0-p2 | |
Checkmk Checkmk | =1.6.0-p3 | |
Checkmk Checkmk | =1.6.0-p4 | |
Checkmk Checkmk | =1.6.0-p5 | |
Checkmk Checkmk | =1.6.0-p6 | |
Checkmk Checkmk | =1.6.0-p7 | |
Checkmk Checkmk | =1.6.0-p8 | |
Checkmk Checkmk | =1.6.0-p9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24908 is a vulnerability in Checkmk before 1.6.0p17 that allows local users to obtain SYSTEM privileges via a Trojan horse shell script in a specific directory.
The severity of CVE-2020-24908 is high with a CVSS score of 7.8.
CVE-2020-24908 affects Checkmk versions before 1.6.0p17.
Local users can exploit CVE-2020-24908 by placing a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.
Yes, the fix for CVE-2020-24908 is included in Checkmk version 1.6.0p17.