216.73.216.6

CVE-2025-39664

· Published 09/10/2025 15:16 · Modified 09/10/2025 15:50

Labels: CVE-2025-39664 2025-10-09CVE-2025-39664CWE-22[email protected]

Essential information

Published
09/10/2025 15:16
Modified
09/10/2025 15:50
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:<2.4.0:p13:*:*:*:*:*:*
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:<2.3.0:p38:*:*:*:*:*:*
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:<2.2.0:p46:*:*:*:*:*:*
checkmk / checkmk cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*

References