Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19936 | Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands. |
| Link | Providers |
|---|---|
| https://checkmk.com/werk/17987 |
|
Fri, 22 Aug 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| CPEs | cpe:2.3:a:checkmk:checkmk:2.1.0:*:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:-:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:b1:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:b2:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:b3:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:b4:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:b5:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:b6:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:b7:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:b8:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:i1:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p10:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p11:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p12:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p13:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p14:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p15:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p16:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p17:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p18:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p19:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p1:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p20:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p21:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p22:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p23:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p24:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p25:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p26:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p27:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p28:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p29:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p2:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p30:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p31:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p32:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p33:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p34:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p35:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p36:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p37:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p38:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p39:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p3:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p40:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p41:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p42:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p43:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p4:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p5:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p6:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p7:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p8:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:p9:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:-:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:b1:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:b2:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:b3:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:b4:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:b5:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:b6:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p10:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p11:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p12:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p13:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p14:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p15:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p16:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p17:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p18:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p19:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p1:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p20:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p21:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p22:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p23:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p24:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p25:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p26:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p27:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p28:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p29:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p2:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p30:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p31:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p32:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p33:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p34:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p3:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p4:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p5:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p6:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p7:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p8:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.3.0:p9:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:-:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:b1:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:b2:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:b3:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:b4:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:b5:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:b6:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:p1:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:p2:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:p3:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:p4:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.4.0:p5:*:*:*:*:*:* |
|
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| Metrics |
cvssV3_1
|
Tue, 08 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Jul 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands. | |
| Title | Livestatus injection in autocomplete endpoint | |
| Weaknesses | CWE-140 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2025-07-08T14:20:25.426Z
Reserved: 2025-04-14T09:52:19.273Z
Link: CVE-2025-32918
Updated: 2025-07-08T14:20:22.474Z
Status : Analyzed
Published: 2025-07-04T08:15:25.520
Modified: 2025-08-22T13:29:48.400
Link: CVE-2025-32918
No data.
OpenCVE Enrichment
No data.
EUVD