CVE-2024-28825: Brute-force protection ineffective for some login methods
Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitates password brute-forcing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.3.0b5 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.2.0p26 - Upgrade
Upgrade
Checkmkto a version that resolves this vulnerability.Fixed in 2.1.0p43
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28825?
CVE-2024-28825 is considered a medium severity vulnerability due to its potential to allow password brute-forcing.
How do I fix CVE-2024-28825?
To mitigate CVE-2024-28825, upgrade to Checkmk version 2.3.0b5 or later, or to 2.2.0p26 or later.
What versions of Checkmk are affected by CVE-2024-28825?
CVE-2024-28825 affects Checkmk versions before 2.3.0b5, as well as 2.2.0p26, 2.1.0p43, and 2.0.0.
What specifically does CVE-2024-28825 affect in Checkmk?
CVE-2024-28825 affects the authentication methods in Checkmk by improperly restricting excessive authentication attempts.
Is CVE-2024-28825 an ongoing risk?
Yes, if not updated, CVE-2024-28825 poses an ongoing risk of brute-force attacks against the authentication system.