CVE-2024-6163: local IP restriction of internal HTTP endpoints
Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Apply a local IP restriction for the internal HTTP endpoints so they are accessible only from internal/local IPs.
Checkmk (internal HTTP endpoints) Local IP restriction = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6163?
CVE-2024-6163 is considered a high severity vulnerability due to its ability to bypass authentication and expose sensitive data.
How do I fix CVE-2024-6163?
To fix CVE-2024-6163, update your Checkmk installation to version 2.3.0p10 or later.
What type of attack can exploit CVE-2024-6163?
CVE-2024-6163 can be exploited by remote attackers to bypass authentication mechanisms.
Which versions of Checkmk are affected by CVE-2024-6163?
CVE-2024-6163 affects Checkmk versions below 2.3.0p10, 2.2.0p31, 2.1.0p46, and up to 2.0.0p39.
Is there a workaround for CVE-2024-6163?
Currently, the only effective resolution for CVE-2024-6163 is to apply the appropriate software update.