CVE-2024-13723

Published Feb 4, 2025

Last updated 22 days ago

Overview

Description
The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
Source
bbf0bd87-ece2-41be-b873-96928ee8fab9
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.2
Impact score
5.9
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

bbf0bd87-ece2-41be-b873-96928ee8fab9
CWE-434

Social media

Hype score
Not currently trending