← Vulnerability feed

Vulnerability record · CVE-2014-0243 · published 19 July 2018

CVE-2014-0243: Check mk project check mk link following vulnerability

Check Mk Project · Check Mk

Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.

5.5 CVSS 3.0 Medium EPSS 0.59% · top 53.7% CWE-59 · Link following
5.5CVSS 3.0 base score, v2 2.1
0.59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://git.mathias-kettner.de/git/?p=check_mk.git%3Ba=commit%3Bh=0426323df1641596c4f01ef5a716a3b65276f01c
http://git.mathias-kettner.de/git/?p=check_mk.git%3Ba=commit%3Bh=a2ef8d00c53ec9cbd05c4ae2f09b50761130e7ce
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134160.html ExploitMailing ListThird Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134166.html ExploitMailing ListThird Party Advisory
http://packetstormsecurity.com/files/126857/Check_MK-Arbitrary-File-Disclosure.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2014/May/145 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2014/05/28/1 ExploitMailing ListThird Party Advisory
http://www.securityfocus.com/bid/67674 Third Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1101669 Issue TrackingPatchThird Party Advisory
https://secuniaresearch.flexerasoftware.com/advisories/58536 Permissions RequiredThird Party Advisory
https://www.securityfocus.com/archive/1/532224/100/0/threaded ExploitThird Party AdvisoryVDB Entry
http://git.mathias-kettner.de/git/?p=check_mk.git%3Ba=commit%3Bh=0426323df1641596c4f01ef5a716a3b65276f01c
http://git.mathias-kettner.de/git/?p=check_mk.git%3Ba=commit%3Bh=a2ef8d00c53ec9cbd05c4ae2f09b50761130e7ce
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134160.html ExploitMailing ListThird Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134166.html ExploitMailing ListThird Party Advisory
http://packetstormsecurity.com/files/126857/Check_MK-Arbitrary-File-Disclosure.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2014/May/145 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2014/05/28/1 ExploitMailing ListThird Party Advisory
http://www.securityfocus.com/bid/67674 Third Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1101669 Issue TrackingPatchThird Party Advisory
https://secuniaresearch.flexerasoftware.com/advisories/58536 Permissions RequiredThird Party Advisory
https://www.securityfocus.com/archive/1/532224/100/0/threaded ExploitThird Party AdvisoryVDB Entry

Track CVE-2014-0243 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-5340Check mk project check mk code injection vulnerabilityThe wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execu…EPSS 6.1%8.5CVE-2014-2331Check mk project check mk code injection vulnerabilityCheck_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. …EPSS 2.1%6.8CVE-2014-2330Check mk project check mk cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authe…EPSS 1.1%6.1CVE-2017-11507Check mk project check mk cross-site scripting vulnerabilityA cross site scripting (XSS) vulnerability exists in Check_MK versions 1.2.8x prior to 1.2.8p25 and 1.4.0x prior to 1.4.0p9, allowing an unauthentica…EPSS 1.0%6.1CVE-2017-9781Check mk project check mk cross-site scripting vulnerabilityA cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject…EPSS 1.6%5.5CVE-2014-2332Check mk project check mk improper input validation vulnerabilityCheck_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, r…EPSS 1.4%4.9CVE-2014-5339Check mk project check mk vulnerabilityCheck_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk files) to arbitrary locations …EPSS 1.8%3.5CVE-2014-2329Check mk project check mk cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject a…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2014-0243), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.