Medium severity5.9NVD Advisory· Published Oct 2, 2017· Updated May 13, 2026
CVE-2017-14955
CVE-2017-14955
Description
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
Affected products
19cpe:2.3:a:checkmk:checkmk:1.2.3:i6:*:*:*:*:*:*+ 18 more
- cpe:2.3:a:checkmk:checkmk:1.2.3:i6:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.3:i7:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.4:b1:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.5:i1:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.5:i2:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.5:i3:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.5:i4:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.5:i5:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.5:i6:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.6:b1:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.6:b2:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.6:p13:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.7:i1:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.7:i1p2:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.7:i2:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.7:i3:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.7:i4:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.8:p18:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.2.8:p25:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- mathias-kettner.com/check_mk_werks.phpnvdRelease NotesThird Party Advisory
- mathias-kettner.de/check_mk_werks.phpnvdThird Party Advisory
- www.exploit-db.com/exploits/43021/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.