Vulnerability Description
SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was deployed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkmk | Checkmk | 2.2.0 |
Related Weaknesses (CWE)
References
- https://checkmk.com/werk/19030Vendor Advisory
FAQ
What is CVE-2025-65000?
CVE-2025-65000 is a vulnerability with a CVSS score of 5.3 (MEDIUM). SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized...
How severe is CVE-2025-65000?
CVE-2025-65000 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-65000?
Check the references section above for vendor advisories and patch information. Affected products include: Checkmk Checkmk.