Medium severity6.1NVD Advisory· Published Mar 25, 2022· Updated Jul 9, 2026
CVE-2021-40906
CVE-2021-40906
Description
CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
39cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*+ 36 more
- cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*range: >=1.5.0,<1.6.0
- cpe:2.3:a:checkmk:checkmk:1.6.0:-:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:b10:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:b12:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:b1:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:b3:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:b4:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:b5:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:b9:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p10:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p11:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p12:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p13:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p14:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p15:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p16:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p19:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p1:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p20:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p21:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p22:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p23:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p24:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p25:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p2:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p3:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p4:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p5:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p6:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p7:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p8:*:*:*:*:*:*
- cpe:2.3:a:checkmk:checkmk:1.6.0:p9:*:*:*:*:*:*
- cpe:2.3:a:tribe29:checkmk:1.6.0b10:*:*:*:*:*:*:*
- cpe:2.3:a:tribe29:checkmk:1.6.0b11:*:*:*:*:*:*:*
- cpe:2.3:a:tribe29:checkmk:1.6.0p10:*:*:*:*:*:*:*
- cpe:2.3:a:tribe29:checkmk:1.6.0p17:*:*:*:*:*:*:*
- cpe:2.3:a:tribe29:checkmk:1.6.0p18:*:*:*:*:*:*:*
- CheckMK/CheckMK Raw Editiondescription
- Range: 1.5.0 - 1.6.0
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.