CVE-2014-5340: Check Mk Project Check Mk

High severity, CVSS 9.3. EPSS: 6.1% chance of exploitation in the next 30 days.

The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to an automation URL.

Affected products

  • Check Mk Project Check Mk: up to and including 1.2.4; version 1.2.4 only; version 1.2.5 only

Published 2014-09-02. Last modified 2026-06-17.