8.8
CVSSv3

CVE-2021-40904

Published: 25/03/2022 Updated: 04/04/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tribe29 checkmk

Github Repositories

CVE-2021-40904 - RCE via CheckMk's Dokuwiki embedded application Application: CheckMK Management Web Console Software Revision: From 150 to 150p25 Attack type: RCE Solution: Upgrade to version 16 or higher Summary: The web management console of CheckMk Raw Edition (versions 150 to 150p25) allows a misconfiguration of the web-app Dokuwiki (installed by default) wh