CVE-2020-28900
Summary
| CVE | CVE-2020-28900 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-24 13:15:00 UTC |
| Updated | 2021-05-28 19:58:00 UTC |
| Description | Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh. |
Risk And Classification
Problem Types: CWE-345
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Nagios XI / Fusion Privilege Escalation / Cross Site Scripting / Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Skylight Cyber | 13 Nagios Vulnerabilities, #7 will SHOCK you! | MISC | skylightcyber.com | |
| Nagios XI Change Log - Nagios | MISC | www.nagios.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 375647 Nagios XI And Nagios Fusion Multiple Vulnerabilities