Checkmk Agent Receiver Denial of Service Vulnerability
A vulnerability in the Checkmk Agent Receiver allows a remote, authenticated attacker to trigger a Denial of Service condition on the affected monitoring infrastructure.
CVE search metadata
CVE search record: CVE-2024-42353. Severity: medium. CVSS: 6.1. EPSS: 0.53%. KEV: no. Product: Checkmk Agent Receiver. Brief: Checkmk Agent Receiver Denial of Service Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-checkmk-dos/
The BSI has reported a vulnerability (CVE-2024-42353) affecting the Checkmk Agent Receiver. This vulnerability permits a remote, authenticated attacker to induce a Denial of Service (DoS) condition on the monitoring system. The issue resides within the mechanism that handles incoming agent data. Because successful exploitation requires an authenticated session, the primary risk involves users with established credentials - such as compromised service accounts or malicious insiders - who can disrupt monitoring services, potentially leading to a lack of visibility into system health or operational failures within the monitored infrastructure. Defenders should review access controls to the Agent Receiver and verify that systems are patched to versions addressing this flaw, as identified by the vendor.
Impact
Successful exploitation results in the disruption of the Checkmk monitoring service, preventing IT administrators from receiving alerts or monitoring the status of infrastructure nodes. This can lead to significant monitoring gaps during critical production outages. The scope of impact is limited to organizations utilizing Checkmk, specifically those where Agent Receiver services are reachable by entities possessing valid, though potentially low-privileged, credentials.
Recommendation
Prioritize the identification and patching of all instances running the affected Checkmk Agent Receiver. Consult the vendor security advisory for the specific version that remediates CVE-2024-42353. Review authentication logs to monitor for unusual patterns or privilege usage associated with accounts accessing the Agent Receiver service.
Mitigations
Upgrade Checkmk Agent Receiver to the version specified by the vendor security advisory addressing CVE-2024-42353.
CVE-2024-42353