Vulnerability Database

309,136

Total vulnerabilities in the database

CVE-2020-24908

Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.

  • Published: Feb 19, 2021
  • Updated: Nov 16, 2025
  • CVE: CVE-2020-24908
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.8
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.2
  • AV:L/AC:L/Au:N/C:C/I:C/A:C

No CWE or OWASP classifications available.

Software From Fixed in
checkmk / checkmk 1.6.0-p5 1.6.0-p5.x
checkmk / checkmk 1.6.0-p6 1.6.0-p6.x
checkmk / checkmk 1.6.0-p7 1.6.0-p7.x
checkmk / checkmk 1.6.0-p8 1.6.0-p8.x
checkmk / checkmk 1.6.0-p9 1.6.0-p9.x
checkmk / checkmk 1.6.0-p10 1.6.0-p10.x
checkmk / checkmk 1.6.0-p11 1.6.0-p11.x
checkmk / checkmk 1.6.0-p12 1.6.0-p12.x
checkmk / checkmk 1.6.0-p13 1.6.0-p13.x
checkmk / checkmk 1.6.0-p14 1.6.0-p14.x
checkmk / checkmk 1.6.0-p15 1.6.0-p15.x
checkmk / checkmk 1.6.0-p16 1.6.0-p16.x
checkmk / checkmk 1.6.0 1.6.0.x
checkmk / checkmk 1.6.0-p4 1.6.0-p4.x
checkmk / checkmk 1.6.0-p3 1.6.0-p3.x
checkmk / checkmk 1.6.0-p2 1.6.0-p2.x
checkmk / checkmk 1.6.0-p1 1.6.0-p1.x
checkmk / checkmk - 1.6.0