icon

We found results for “

CVE-2025-64996

Good to know:

icon
icon

Date: November 18, 2025

In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data.

Severity Score

Severity Score

Weakness Type (CWE)

Incorrect Permission Assignment for Critical Resource

CWE-732

Top Fix

icon

Upgrade Version

Upgrade to version https://github.com/Checkmk/checkmk.git - v2.4.0p16;https://github.com/Checkmk/checkmk.git - v2.4.0p16;https://github.com/Checkmk/checkmk.git - v2.4.0p16;https://github.com/Checkmk/checkmk.git - v2.4.0p16

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): NONE
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us