We found results for “”
CVE-2025-64996
Good to know:
Date: November 18, 2025
In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data.
Severity Score
Severity Score
Weakness Type (CWE)
Incorrect Permission Assignment for Critical Resource
CWE-732Top Fix
Upgrade Version
Upgrade to version https://github.com/Checkmk/checkmk.git - v2.4.0p16;https://github.com/Checkmk/checkmk.git - v2.4.0p16;https://github.com/Checkmk/checkmk.git - v2.4.0p16;https://github.com/Checkmk/checkmk.git - v2.4.0p16
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | LOCAL |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


