Описание
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.
Ссылки
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.8 (включая)Версия до 5.7.5 (включая)
Одно из
cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00794
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-345
Связанные уязвимости
github
больше 3 лет назад
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.
EPSS
Процентиль: 74%
0.00794
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-345