Vulnerability Name: | CVE-2020-28907 (CCN-202381) | ||||||||||||
Assigned: | 2020-11-17 | ||||||||||||
Published: | 2021-05-20 | ||||||||||||
Updated: | 2021-06-03 | ||||||||||||
Summary: | Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-295 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-28907 Source: MISC Type: Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html Source: XF Type: UNKNOWN nagiosfusion-cve202028907-priv-esc(202381) Source: CCN Type: Skylight Web site 13 Nagios Vulnerabilities, #7 will SHOCK you! Source: MISC Type: Exploit, Third Party Advisory https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/ Source: MISC Type: Release Notes, Vendor Advisory https://www.nagios.com/downloads/nagios-xi/change-log/ Source: CCN Type: Nagios Web site Nagios Fusion | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |