CVE-2024-13723 – Checkmk NagVis Remote Code Execution Vulnerability

The following table lists the changes that have been made to the
CVE-2024-13723 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by bbf0bd87-ece2-41be-b873-96928ee8fab9

    Feb. 04, 2025

    Action Type Old Value New Value
    Added Description The “NagVis” component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
    Added CWE CWE-434
    Added Reference https://checkmk.com/werks?version=2.3.0p10
    Added Reference https://korelogic.com/Resources/Advisories/KL-001-2025-002.txt
    Added Reference https://www.nagvis.org/downloads/changelog/1.9.42
Share the Post:

Related Posts