{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apylonsprojectwebob/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*","cpe:2.3:a:pylonsproject:webob:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.1,"id":"CVE-2024-42353"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Checkmk Agent Receiver"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["Checkmk"],"content_html":"\u003cp\u003eThe BSI has reported a vulnerability (CVE-2024-42353) affecting the Checkmk Agent Receiver. This vulnerability permits a remote, authenticated attacker to induce a Denial of Service (DoS) condition on the monitoring system. The issue resides within the mechanism that handles incoming agent data. Because successful exploitation requires an authenticated session, the primary risk involves users with established credentials - such as compromised service accounts or malicious insiders - who can disrupt monitoring services, potentially leading to a lack of visibility into system health or operational failures within the monitored infrastructure. Defenders should review access controls to the Agent Receiver and verify that systems are patched to versions addressing this flaw, as identified by the vendor.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the disruption of the Checkmk monitoring service, preventing IT administrators from receiving alerts or monitoring the status of infrastructure nodes. This can lead to significant monitoring gaps during critical production outages. The scope of impact is limited to organizations utilizing Checkmk, specifically those where Agent Receiver services are reachable by entities possessing valid, though potentially low-privileged, credentials.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all instances running the affected Checkmk Agent Receiver. Consult the vendor security advisory for the specific version that remediates CVE-2024-42353. Review authentication logs to monitor for unusual patterns or privilege usage associated with accounts accessing the Agent Receiver service.\u003c/p\u003e\n","date_modified":"2026-09-04T18:06:30Z","date_published":"2026-09-04T18:06:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-checkmk-dos/","summary":"A vulnerability in the Checkmk Agent Receiver allows a remote, authenticated attacker to trigger a Denial of Service condition on the affected monitoring infrastructure.","title":"Checkmk Agent Receiver Denial of Service Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-checkmk-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:pylonsproject:webob:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}