{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-28826","assignerOrgId":"f7d6281c-4801-44ce-ace2-493291dedb0f","state":"PUBLISHED","assignerShortName":"Checkmk","dateReserved":"2024-03-11T13:21:43.122Z","datePublished":"2024-05-29T10:00:53.789Z","dateUpdated":"2024-08-02T00:56:58.127Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Checkmk","vendor":"Checkmk GmbH","versions":[{"lessThan":"2.3.0p4","status":"affected","version":"2.3.0","versionType":"semver"},{"lessThan":"2.2.0p27","status":"affected","version":"2.2.0","versionType":"semver"},{"lessThan":"2.1.0p44","status":"affected","version":"2.1.0","versionType":"semver"},{"lessThanOrEqual":"2.0.0p39","status":"affected","version":"2.0.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server."}],"impacts":[{"capecId":"CAPEC-212","descriptions":[{"lang":"en","value":"CAPEC-212: Functionality Misuse"}]}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-73","description":"CWE-73: External Control of File Name or Path","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"f7d6281c-4801-44ce-ace2-493291dedb0f","shortName":"Checkmk","dateUpdated":"2024-05-29T10:00:53.789Z"},"references":[{"url":"https://checkmk.com/werk/15200"}],"title":"Unrestricted upload and download paths in check_sftp"},"adp":[{"affected":[{"vendor":"checkmk","product":"checkmk","cpes":["cpe:2.3:a:checkmk:checkmk:2.0.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"2.0.0","status":"affected","lessThan":"2.0.0p39","versionType":"semver"}]},{"vendor":"checkmk","product":"checkmk","cpes":["cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"2.1.0","status":"affected","lessThan":"2.1.0p44","versionType":"semver"}]},{"vendor":"checkmk","product":"checkmk","cpes":["cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"2.2.0","status":"affected","lessThan":"2.2.0p27","versionType":"semver"}]},{"vendor":"checkmk","product":"checkmk","cpes":["cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"2.3.0","status":"affected","lessThan":"2.3.0p4","versionType":"semver"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-05T20:21:05.131648Z","id":"CVE-2024-28826","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-05T20:33:54.922Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T00:56:58.127Z"},"title":"CVE Program Container","references":[{"url":"https://checkmk.com/werk/15200","tags":["x_transferred"]}]}]}}