PT-2018-13424 · Opsview · Opsview Monitor

Fernando Catoira

+1

·

Published

2018-09-05

·

Updated

2019-10-03

·

CVE-2018-16146

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Opsview Monitor versions 5.4.x through 5.4.1
Description The issue affects the web management console, where an authenticated administrator can exploit a command injection flaw due to improper sanitization of the value parameter. This allows for arbitrary command execution with the privileges of the nagios user account.
Recommendations For Opsview Monitor versions 5.4.x through 5.4.1, update to version 5.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the web management console to minimize the risk of exploitation. Avoid using the value parameter in the affected functionality until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16146

Affected Products

Opsview Monitor