CVE-2025-64997
MEDIUMDescription
Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view agent information via the REST API, which could lead to information disclosure.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
| checkmk | checkmk |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-64997? +
How severe is CVE-2025-64997? +
What products are affected by CVE-2025-64997? +
How do I check if I'm vulnerable to CVE-2025-64997? +
Related Vulnerabilities
An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated …
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to …
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.
Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to …