Vulnerability Name: | CCN-81940 | ||||||
Published: | 2013-02-02 | ||||||
Updated: | 2013-02-02 | ||||||
Summary: | Nagios XI could allow a remote attacker to execute arbitrary commands on the system, caused by an error in Autodiscovery module. An attacker could exploit this vulnerability using the address POST parameter to inject and execute arbitrary shell commands on the system. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Sat Feb 02 2013 Multiple Vulnerabilities: Nagios XI 2012R1.5b Source: CCN Type: SA52011 Nagios XI Multiple Vulnerabilities Source: CCN Type: Nagios XI Web site Nagios - Nagios XI Source: XF Type: UNKNOWN nagiosxi-autodiscovery-command-execution(81940) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |