Insecure Symmetric Encryption in Tribe29 Checkmk Versions

Insecure Symmetric Encryption in Tribe29 Checkmk Versions

CVE-2023-1768 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.

Learn more about our Web Application Penetration Testing UK.