{"api_version":"1","generated_at":"2026-07-23T21:14:17+00:00","cve":"CVE-2020-28900","urls":{"html":"https://cve.report/CVE-2020-28900","api":"https://cve.report/api/cve/CVE-2020-28900.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-28900","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-28900"},"summary":{"title":"CVE-2020-28900","description":"Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-05-24 13:15:00","updated_at":"2021-05-28 19:58:00"},"problem_types":["CWE-345"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html","name":"http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html","refsource":"MISC","tags":[],"title":"Nagios XI / Fusion Privilege Escalation / Cross Site Scripting / Code Execution ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/","name":"https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/","refsource":"MISC","tags":[],"title":"Skylight Cyber | 13 Nagios Vulnerabilities, #7 will SHOCK you!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.nagios.com/downloads/nagios-xi/change-log/","name":"https://www.nagios.com/downloads/nagios-xi/change-log/","refsource":"MISC","tags":[],"title":"Nagios XI Change Log - Nagios","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-28900","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28900","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"28900","vulnerable":"1","versionEndIncluding":"4.1.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nagios","cpe5":"fusion","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"28900","vulnerable":"1","versionEndIncluding":"5.7.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nagios","cpe5":"nagios_xi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-28900","qid":"375647","title":"Nagios XI And Nagios Fusion Multiple Vulnerabilities"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-28900","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.nagios.com/downloads/nagios-xi/change-log/","refsource":"MISC","name":"https://www.nagios.com/downloads/nagios-xi/change-log/"},{"refsource":"MISC","name":"https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/","url":"https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html","url":"http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html"}]}},"nvd":{"publishedDate":"2021-05-24 13:15:00","lastModifiedDate":"2021-05-28 19:58:00","problem_types":["CWE-345"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*","versionEndIncluding":"4.1.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*","versionEndIncluding":"5.7.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"28900","Ordinal":"191962","Title":"CVE-2020-28900","CVE":"CVE-2020-28900","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"28900","Ordinal":"1","NoteData":"Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"28900","Ordinal":"2","NoteData":"2021-05-24","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"28900","Ordinal":"3","NoteData":"2021-05-26","Type":"Other","Title":"Modified"}]}}}