Vulnerability Description
Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkmk | Checkmk | < 1.6.0 |
References
- https://compass-security.com/fileadmin/Research/Advisories/2020-05_CSNC-2020-005Third Party Advisory
- https://compass-security.com/fileadmin/Research/Advisories/2020-05_CSNC-2020-005Third Party Advisory
FAQ
What is CVE-2020-24908?
CVE-2020-24908 is a vulnerability with a CVSS score of 7.8 (HIGH). Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.
How severe is CVE-2020-24908?
CVE-2020-24908 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24908?
Check the references section above for vendor advisories and patch information. Affected products include: Checkmk Checkmk.