9.3
CVSSv2

CVE-2014-5340

Published: 02/09/2014 Updated: 09/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The wato component in Check_MK prior to 1.2.4p4 and 1.2.5 prior to 1.2.5i4 uses the pickle Python module unsafely, which allows remote malicious users to execute arbitrary code via a crafted serialized object, related to an automation URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

check mk project check mk 1.2.4

check mk project check mk 1.2.5

check mk project check mk

Vendor Advisories

Debian Bug report logs - #758883 check-mk: CVE-2014-5338 CVE-2014-5339 CVE-2014-5340 Package: src:check-mk; Maintainer for src:check-mk is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Aug 2014 12:06:01 UTC Severity: grav ...
The wato component in Check_MK before 124p4 and 125 before 125i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to an automation URL ...