Database/Control plane, storage & DevOps
Checkmk REST API: host configuration GET responses return SNMP and IPMI credentials in clear text
Impact
Any Checkmk user allowed to view a host's configuration can read back stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in plain text from REST API GET responses, even though the setup GUI deliberately masks them. In a datacenter the monitoring system holds the IPMI credentials for every BMC and the SNMP credentials for the switches and PDUs, so a low-privileged monitoring account becomes a credential harvest for the management plane - the same BMC passwords that grant console, virtual media and power control on GPU nodes. The flaw is read-only credential exposure, not direct code execution, but the recovered credentials are reusable against hardware that is rarely rotated.
Who can reach it
Any authenticated Checkmk user with permission to view host or folder configuration, over the network to the Checkmk site's REST API. No administrative role needed.
What to do
Upgrade to Checkmk 2.5.0p15, 2.4.0p38 or 2.3.0p51 or later and restart the site; 2.2.0 is end of life and will not be fixed, so those installations must be migrated. Patching stops further disclosure but does not undo it: rotate any SNMP community strings, SNMPv3 pass phrases and IPMI passwords that were readable, which is the expensive part since IPMI password changes touch every BMC. Review which users hold host-configuration view rights.
References
Related entries
- DMTF libspdm CSR generation under the mbedTLS crypto backend (cryptlib_mbedtls): Stack corruption inside the firmwareNCVD-2026-006-dmtf-libspdm-csr-generation-unde · DMTF libspdm CSR generation under the mbedTLS crypto backend (cryptlib_mbedtls)Medium
- DMTF libspdm responder handling of GET_MEASUREMENT_EXTENSION_LOG: A requester reads memory it was never authorisedNCVD-2026-007-dmtf-libspdm-responder-handling · DMTF libspdm responder handling of GET_MEASUREMENT_EXTENSION_LOGMedium
- rclone (rc server, /debug/pprof handler): The pprof debug handler is mounted as its own route on the rcloneNCVD-2026-041-rclone-rc-server-debug-pprof-han · rclone (rc server, /debug/pprof handler)Medium
- Nagios XI: systemd unit files shipped with unnecessary executable permissionsCVE-2025-34135 · Nagios XI (nagios.service systemd unit file permissions)Medium
- Zabbix frontend: host search filters on hidden fields, turning stored IPMI and PSK secrets into a guessing oracleCVE-2026-59785 · Zabbix frontend (host search filter over non-displayed fields)Medium
- Keycloak: OIDC authentication flaw - attacker reusing data from a same-realm request impersonates a userCVE-2023-0264 · KeycloakMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.