Описание
Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.
Ссылки
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.8 (включая)
cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.0065
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-295
Связанные уязвимости
github
больше 3 лет назад
Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.
EPSS
Процентиль: 70%
0.0065
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-295