CVE-2021-37345

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
13/08/2021
Last modified:
23/08/2021

Description

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* 5.8.5 (excluding)