CVE-2024-13723
Last modified
CVE-2024-13723 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-13723?
How severe is CVE-2024-13723?
How do I fix CVE-2024-13723?
Are you affected by CVE-2024-13723?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
