CVE Vulnerabilities

CVE-2024-6572

Key Exchange without Entity Authentication

Published: Sep 09, 2024 | Modified: Sep 09, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Improper host key checking in active check Check SFTP Service and special agent VNX quotas and filesystem in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic

Weakness

The product performs a key exchange with an actor without verifying the identity of that actor.

Potential Mitigations

References