CVE-2018-8733
Summary
| CVE | CVE-2018-8733 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-18 00:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root - PHP webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE-2018-873X - NagiosXI Vulnerability Chaining; Death By a Thousand Cuts | Redacted Security Blog | MISC | blog.redactedsec.net | Exploit, Technical Description, Third Party Advisory |
| Nagios XI Change Log - Nagios | MISC | www.nagios.com | Release Notes, Vendor Advisory |
| NagiosXI remote root vulnerability CVE-2018-8733, CVE-2018-8734, CVE-2018-8735, CVE-2018-8736 · GitHub | MISC | gist.github.com | Third Party Advisory |
| Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit) | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT | MISC | assets.nagios.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.