Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.
History

Thu, 28 Aug 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Checkmk
Checkmk checkmk
Vendors & Products Checkmk
Checkmk checkmk

Thu, 28 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Aug 2025 13:15:00 +0000

Type Values Removed Values Added
Description Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.
Title Lack of TLS validation in plugin check-mk-api on Checkmk Exchange
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published:

Updated: 2025-08-28T13:18:44.095Z

Reserved: 2025-08-25T11:50:49.622Z

Link: CVE-2025-58124

cve-icon Vulnrichment

Updated: 2025-08-28T13:18:39.474Z

cve-icon NVD

Status : Received

Published: 2025-08-28T13:16:09.977

Modified: 2025-08-28T13:16:09.977

Link: CVE-2025-58124

cve-icon Redhat

No data.