Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic
The product performs a key exchange with an actor without verifying the identity of that actor.
Link | Tags |
---|---|
https://checkmk.com/werk/17148 |