CVE-2020-28900

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
24/05/2021
Last modified:
28/05/2021

Description

Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:* 4.1.8 (including)
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* 5.7.5 (including)