CVE-2017-14955
medium · 5.9Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
5.9
CVSS
12.1%
EPSS (exploit prob.)
96th
EPSS percentile
2017-10-02
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-200CWE-362
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| checkmk | checkmk | 1.2.3 |
| checkmk | checkmk | 1.2.3 |
| checkmk | checkmk | 1.2.4 |
| checkmk | checkmk | 1.2.5 |
| checkmk | checkmk | 1.2.5 |
| checkmk | checkmk | 1.2.5 |
| checkmk | checkmk | 1.2.5 |
| checkmk | checkmk | 1.2.5 |
| checkmk | checkmk | 1.2.5 |
| checkmk | checkmk | 1.2.6 |
| checkmk | checkmk | 1.2.6 |
| checkmk | checkmk | 1.2.6 |
| checkmk | checkmk | 1.2.7 |
| checkmk | checkmk | 1.2.7 |
| checkmk | checkmk | 1.2.7 |
| checkmk | checkmk | 1.2.7 |
| checkmk | checkmk | 1.2.7 |
| checkmk | checkmk | 1.2.8 |
| checkmk | checkmk | 1.2.8 |
Check a specific version with /api/v1/cve/match.
References
- http://mathias-kettner.com/check_mk_werks.php?edition_id=raw&branch=1.2.8
- https://mathias-kettner.de/check_mk_werks.php?werk_id=5208&HTML=yes
- https://www.exploit-db.com/exploits/43021/
- http://mathias-kettner.com/check_mk_werks.php?edition_id=raw&branch=1.2.8
- https://mathias-kettner.de/check_mk_werks.php?werk_id=5208&HTML=yes
- https://www.exploit-db.com/exploits/43021/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-14955