SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was deployed.
References
History

Thu, 18 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
Description SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was deployed.
Title Exposure of SSH Private Keys in Remote Alert Handlers (Linux) Rule
First Time appeared Checkmk
Checkmk checkmk
Weaknesses CWE-212
CPEs cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.3.0:*:*:*:*:*:*:*
Vendors & Products Checkmk
Checkmk checkmk
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published:

Updated: 2025-12-18T15:28:51.856Z

Reserved: 2025-11-12T09:16:24.095Z

Link: CVE-2025-65000

cve-icon Vulnrichment

Updated: 2025-12-18T15:28:43.968Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-18T14:15:59.947

Modified: 2025-12-18T15:07:18.427

Link: CVE-2025-65000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.