The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
CVE ID: CVE-2024-13723
Vendor: Checkmk
Product: NagVis
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 18.33% (scored less or equal to compared to others)
EPSS Date: 2025-03-05 (when was this score calculated)