CVE-2020-28907
Summary
| CVE | CVE-2020-28907 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-24 13:15:00 UTC |
| Updated | 2021-06-03 16:31:00 UTC |
| Description | Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Nagios XI / Fusion Privilege Escalation / Cross Site Scripting / Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Skylight Cyber | 13 Nagios Vulnerabilities, #7 will SHOCK you! | MISC | skylightcyber.com | |
| Nagios XI Change Log - Nagios | MISC | www.nagios.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 375647 Nagios XI And Nagios Fusion Multiple Vulnerabilities