CVE-2024-13723: Checkmk NagVis Remote Code Execution
Published Feb 4, 2025
·Updated
The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
Affected Software
1 affected component
CheckMK NagVis
Event History
Feb 4, 2025
CVE Published
via MITRE·10:02 PM
Data Sourced
via MITRE·10:02 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13723?
CVE-2024-13723 is a critical vulnerability that allows remote code execution.
2
How do I fix CVE-2024-13723?
To fix CVE-2024-13723, upgrade the NagVis component within Checkmk to the latest patched version.
3
Who can exploit CVE-2024-13723?
An authenticated attacker with administrative privileges can exploit CVE-2024-13723.
4
What type of vulnerability is CVE-2024-13723?
CVE-2024-13723 is classified as a remote code execution vulnerability.
5
What components are affected by CVE-2024-13723?
CVE-2024-13723 affects the NagVis component within Checkmk.