CVE-2021-40904: High severity CheckMK Checkmk vulnerability
The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Fix the web-app Dokuwiki misconfiguration in the CheckMK web management console (affects CheckMK Raw Edition versions 1.5.0 to 1.6.0) so embedded php code is not permitted.
Dokuwiki (web-app installed by default in CheckMK web management console) Embedded PHP code handling/misconfiguration = Disable the misconfiguration that allows embedded php code - Compensating control
Restrict access to the CheckMK web management interface so only trusted users/sources can reach it (remote code execution requires access to this interface with administrator role via valid credentials or hijacked session).
Event History
Frequently Asked Questions
What is CVE-2021-40904?
CVE-2021-40904 is a vulnerability in the web management console of CheckMK Raw Edition that allows a misconfiguration of the web-app Dokuwiki, resulting in remote code execution.
What is the severity of CVE-2021-40904?
CVE-2021-40904 has a severity rating of 8.8 (high).
What software versions are affected by CVE-2021-40904?
Versions 1.5.0 to 1.6.0 of the CheckMK Raw Edition are affected by CVE-2021-40904.
How can CVE-2021-40904 be exploited?
CVE-2021-40904 can be exploited by achieving access to the web management interface and exploiting a misconfiguration in the web-app Dokuwiki to execute remote code.
Is there a fix for CVE-2021-40904?
At the moment, there is no official fix available for CVE-2021-40904. It is recommended to keep the software up to date and apply any patches or security updates released by the vendor.