Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.
References
History

Thu, 22 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 22 May 2025 14:30:00 +0000

Type Values Removed Values Added
Description Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.
Title Sensitive data exposed during automatic agent updates
Weaknesses CWE-732
References
Metrics cvssV4_0

{'score': 4.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published: 2025-05-22T14:16:01.214Z

Updated: 2025-05-22T14:48:38.894Z

Reserved: 2025-04-14T09:52:19.272Z

Link: CVE-2025-32915

cve-icon Vulnrichment

Updated: 2025-05-22T14:48:33.722Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-22T15:16:04.870

Modified: 2025-05-23T15:55:02.040

Link: CVE-2025-32915

cve-icon Redhat

No data.