CVE-2023-1768CWE-446

Symmetric agent data encryption fails silently

Low · published April 4, 2023

CVSS v3.1
3.7
EPSS
1%
Percentile
57.8
In the wild
Unconfirmed
What it is

Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.

The record
Technical detail
CVSS v3.1
3.7 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00913 · 57.8th percentile
Weakness
CWE-446 · UI Discrepancy for Security Feature
Published
2023-04-04T06:30Z
EPSS history
Timeline
  • 04 APR 06:30Z
    Symmetric agent data encryption fails silently
    cvelistv5