CVE-2025-64997
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
18/12/2025
Last modified:
23/12/2025
Description
Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view agent information via the REST API, which could lead to information disclosure.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:b1:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:b2:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:b3:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:b4:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:b5:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:b6:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:p1:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:p10:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:p11:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:p12:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:p13:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:p14:*:*:*:*:*:* | ||
| cpe:2.3:a:checkmk:checkmk:2.3.0:p15:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



