{"id":"CVE-2024-28833","summary":"Missing brute-force protection for two factor authentication","details":"Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms.","modified":"2026-08-12T03:51:47.912073781Z","published":"2024-06-10T11:55:50.571Z","database_specific":{"cwe_ids":["CWE-307"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28833.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2.3.0"},{"fixed":"2.3.0p6"}]},{"source":"DESCRIPTION","extracted_events":[{"introduced":"2.3"},{"fixed":"2.3.0p6"}]}],"cna_assigner":"Checkmk"},"references":[{"type":"WEB","url":"https://checkmk.com/werk/16830"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28833.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28833"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/checkmk/checkmk","events":[{"introduced":"774354b2551f8e27948fc4cebfc950ee81d28e0d"},{"last_affected":"1fc0aea14b848c3d4eaf779a42ac59e3af0e8df6"}],"database_specific":{"extracted_events":[{"introduced":"2.3.0-p1"},{"last_affected":"2.3.0-p1"},{"introduced":"2.3.0-p2"},{"last_affected":"2.3.0-p2"},{"introduced":"2.3.0-p3"},{"last_affected":"2.3.0-p3"},{"introduced":"2.3.0-p4"},{"last_affected":"2.3.0-p4"},{"introduced":"2.3.0-p5"},{"last_affected":"2.3.0-p5"}],"source":"CPE_STRING","cpe":["cpe:2.3:a:checkmk:checkmk:2.3.0:p1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.3.0:p5:*:*:*:*:*:*"]}}],"versions":["2.3.0-p1","2.3.0-p2","2.3.0-p3","2.3.0-p4","2.3.0-p5","v2.3.0p5-rc1","v2.3.0p5","v2.3.0p4-rc1","v2.3.0p4","v2.3.0p3-rc1","v2.3.0p2-rc1","v2.3.0p2","v2.3.0p1-rc1","v2.3.0p1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28833.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}