CVE-2014-5340

critical
Published 2014-09-02 · Modified 2026-05-06
CVSS v3
CVSS v2
9.3
VIR risk
9.3

Description

The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to an automation URL.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://mathias-kettner.de/check_mk_werks.php?werk_id=984

Application impact

VendorProductVersionsFixed
check_mk_projectcheck_mk{"endIncluding":"1.2.4"}
check_mk_projectcheck_mk1.2.4
check_mk_projectcheck_mk1.2.5

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.