CVE-2025-58124: Lack of TLS validation in plugin check-mk-api on Checkmk Exchange
Published Aug 28, 2025
·Updated
Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.
Affected Software
2 affected components
Checkmk check-mk-api
Heinlein-support Check Mk Python Api Checkmk
Event History
Aug 28, 2025
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
DescriptionWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58124?
CVE-2025-58124 is classified as a high-severity vulnerability due to improper certificate validation that enables man-in-the-middle attacks.
2
How do I fix CVE-2025-58124?
To fix CVE-2025-58124, ensure that proper certificate validation is implemented within the Checkmk check-mk-api configuration.
3
What software is affected by CVE-2025-58124?
CVE-2025-58124 affects the Checkmk check-mk-api plugin.
4
What types of attacks can CVE-2025-58124 facilitate?
CVE-2025-58124 can facilitate man-in-the-middle (MitM) attacks, allowing attackers to intercept sensitive traffic.
5
What is the impact of exploiting CVE-2025-58124?
Exploiting CVE-2025-58124 could lead to unauthorized data interception and exposure, compromising the integrity and confidentiality of the transmitted information.