GPU VulnDB

Database/Control plane, storage & DevOps

Checkmk REST API: host configuration GET responses return SNMP and IPMI credentials in clear text

CVSS 5.3CVE-2026-92882Control plane, storage & DevOpscurated

Impact

Any Checkmk user allowed to view a host's configuration can read back stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in plain text from REST API GET responses, even though the setup GUI deliberately masks them. In a datacenter the monitoring system holds the IPMI credentials for every BMC and the SNMP credentials for the switches and PDUs, so a low-privileged monitoring account becomes a credential harvest for the management plane - the same BMC passwords that grant console, virtual media and power control on GPU nodes. The flaw is read-only credential exposure, not direct code execution, but the recovered credentials are reusable against hardware that is rarely rotated.

Who can reach it

Any authenticated Checkmk user with permission to view host or folder configuration, over the network to the Checkmk site's REST API. No administrative role needed.

What to do

Upgrade to Checkmk 2.5.0p15, 2.4.0p38 or 2.3.0p51 or later and restart the site; 2.2.0 is end of life and will not be fixed, so those installations must be migrated. Patching stops further disclosure but does not undo it: rotate any SNMP community strings, SNMPv3 pass phrases and IPMI passwords that were readable, which is the expensive part since IPMI password changes touch every BMC. Review which users hold host-configuration view rights.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.