PT-2021-11597 · Nagios · Nagios Fusion+1

Published

2021-05-24

·

Updated

2021-05-28

·

CVE-2020-28906

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Nagios XI versions 5.7.5 and earlier Nagios Fusion versions 4.1.8 and earlier
Description: The issue allows low-privileged users to modify files that are included by scripts executed by root, leading to privilege escalation to root. This is due to incorrect file permissions in the affected software.
Recommendations: For Nagios XI versions 5.7.5 and earlier, update to a version later than 5.7.5 to resolve the issue. For Nagios Fusion versions 4.1.8 and earlier, update to a version later than 4.1.8 to resolve the issue. As a temporary workaround, consider restricting access to the files that are included by scripts executed by root to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28906

Affected Products

Nagios Fusion
Nagios Xi