QID 376139
Date Published: 2022-03-21
QID 376139: Checkmk Agent Unauthenticated Information Disclosure Vulnerability
Checkmk is an IT infrastructure monitoring software. It is consists of a management server querying the clients and of an agent installed on the monitored systems.
The CHECKMK agent, which defaults to TCP port 6556 exposes sensitive information regarding the running services and flags, from the system over an unauthenticated and unencrypted connection.
QID Detection Logic (Authenticated) :
This QID work as service discovery and will knock the ports and flag it if found exposed sensitive information of checkmk agent.
Successful exploitation of this vulnerability may allow sensitive information disclosure to an unauthenticated attacker.
Solution
Instead of using default unauthenticated service, use SSH.Workaround:
The documentation Checkmk Documentation highlights the methodology to leverage SSH instead of their default unauthenticated service.
The documentation Checkmk Documentation highlights the methodology to leverage SSH instead of their default unauthenticated service.
Vendor References
CVEs related to QID 376139
Software Advisories
| Advisory ID | Software | Component | Link |
|---|