Security Advisory

CVE-2025-64996

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-11-18 15:10:53
Last updated 2025-11-18 21:23:15
Assigner Checkmk
CVSS score 4.8
State PUBLISHED

Description

In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data.