CVE-2024-28825: Checkmk

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitates password brute-forcing.

Affected products

  • Checkmk Checkmk: up to and including 2.0.0; version 2.1.0 only; version 2.2.0 only; version 2.3.0 only

Published 2024-04-24. Last modified 2026-06-17.