CVE-2024-8606: Fix 2FA bypass via RestAPI
Published Sep 23, 2024
·Updated
Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication
Affected Software
49 affected components
CheckMK Checkmk=2.3.0
CheckMK Checkmk=2.3.0-p1
CheckMK Checkmk=2.3.0-p10
CheckMK Checkmk=2.3.0-p11
CheckMK Checkmk=2.3.0-p12
CheckMK Checkmk=2.3.0-p13
CheckMK Checkmk=2.3.0-p14
CheckMK Checkmk=2.3.0-p15
CheckMK Checkmk=2.3.0-p2
CheckMK Checkmk=2.3.0-p3
CheckMK Checkmk=2.3.0-p4
CheckMK Checkmk=2.3.0-p5
CheckMK Checkmk=2.3.0-p6
CheckMK Checkmk=2.3.0-p7
CheckMK Checkmk=2.3.0-p8
CheckMK Checkmk=2.3.0-p9
CheckMK Checkmk=2.2.0
CheckMK Checkmk=2.2.0-p1
CheckMK Checkmk=2.2.0-p10
CheckMK Checkmk=2.2.0-p11
CheckMK Checkmk=2.2.0-p12
CheckMK Checkmk=2.2.0-p13
CheckMK Checkmk=2.2.0-p14
CheckMK Checkmk=2.2.0-p15
CheckMK Checkmk=2.2.0-p16
CheckMK Checkmk=2.2.0-p17
CheckMK Checkmk=2.2.0-p18
CheckMK Checkmk=2.2.0-p19
CheckMK Checkmk=2.2.0-p2
CheckMK Checkmk=2.2.0-p20
CheckMK Checkmk=2.2.0-p21
CheckMK Checkmk=2.2.0-p22
CheckMK Checkmk=2.2.0-p23
CheckMK Checkmk=2.2.0-p24
CheckMK Checkmk=2.2.0-p25
CheckMK Checkmk=2.2.0-p26
CheckMK Checkmk=2.2.0-p27
CheckMK Checkmk=2.2.0-p28
CheckMK Checkmk=2.2.0-p29
CheckMK Checkmk=2.2.0-p3
CheckMK Checkmk=2.2.0-p30
CheckMK Checkmk=2.2.0-p31
CheckMK Checkmk=2.2.0-p33
CheckMK Checkmk=2.2.0-p4
CheckMK Checkmk=2.2.0-p5
CheckMK Checkmk=2.2.0-p6
CheckMK Checkmk=2.2.0-p7
CheckMK Checkmk=2.2.0-p8
CheckMK Checkmk=2.2.0-p9
Event History
Sep 23, 2024
CVE Published
via MITRE·07:01 AM
Data Sourced
via MITRE·07:01 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-8606?
The severity of CVE-2024-8606 is classified as a medium vulnerability due to the ability of authenticated users to bypass two-factor authentication.
2
How do I fix CVE-2024-8606?
To fix CVE-2024-8606, upgrade Checkmk to version 2.3.0p16 or 2.2.0p34 or later.
3
Who is affected by CVE-2024-8606?
CVE-2024-8606 affects authenticated users of Checkmk versions prior to 2.3.0p16 and 2.2.0p34.
4
What is the impact of CVE-2024-8606?
The impact of CVE-2024-8606 allows authenticated users to bypass the two-factor authentication mechanism.
5
Is there a workaround for CVE-2024-8606?
There are no known workarounds for CVE-2024-8606 other than applying the appropriate software updates.