CVE-2024-28833: Missing brute-force protection for two factor authentication
Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28833?
CVE-2024-28833 is considered a high severity vulnerability due to its potential for brute-force attacks on two-factor authentication mechanisms.
How do I fix CVE-2024-28833?
To fix CVE-2024-28833, upgrade Checkmk to version 2.3.0p6 or later, which addresses the improper restriction of excessive authentication attempts.
Which Checkmk versions are affected by CVE-2024-28833?
CVE-2024-28833 affects Checkmk versions 2.3.0p1 through 2.3.0p5.
What type of attack does CVE-2024-28833 facilitate?
CVE-2024-28833 facilitates brute-forcing of second factor mechanisms due to improper restrictions on authentication attempts.
Is there a workaround for CVE-2024-28833?
There is no specific workaround available for CVE-2024-28833; upgrading to the patched version is recommended.