CyberRota Analysis
AI-GeneratedImproper certificate validation in Checkmk versions prior to 2.5.0p10 allows relay and push agents with the same UUID to misuse each other's mTLS certificates for authentication, potentially leading to unauthorized access to agent receiver endpoints. This vulnerability could enable attackers to impersonate legitimate agents, compromising the integrity of the system. Organizations using Checkmk should prioritize addressing this issue to safeguard their network communications.
Original NVD Description
Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in either direction, because the endpoints do not verify that the certificate was issued by their own root certificate.