VDB
CVE-2014-5340
CVE-2014-5340
PUBLISHED
Reported by mitre · Published September 2, 2014
The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to an automation URL.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Sep 2, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 14, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 20140820 Deutsche Telekom CERT Advisory [DTC-A-20140820-001] check_mk vulnerabilities mailing-listx_refsource_BUGTRAQ
- RHSA-2015:1495 vendor-advisoryx_refsource_REDHAT
- x_refsource_MISC
- x_refsource_CONFIRM