Overly broad file permissions in the mk_inotify plugin allows reading and manipulating the plugin's output
Vulnerability Description
In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64996
Credits & Attribution
No credits recorded in the NVD database.
References
More from Checkmk GmbH
View All →Affected Vendor
Checkmk GmbH
View all reports →