CVE-2018-15710: OS Command Injection
Published Nov 14, 2018
·Updated
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscovernew.php.
Affected Software
1 affected component
Nagios Nagios XI=5.5.6
Event History
Nov 14, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-15710?
CVE-2018-15710 has a high severity rating due to its ability to allow privilege escalation to root via a vulnerable script.
2
How do I fix CVE-2018-15710?
To fix CVE-2018-15710, it is recommended to upgrade Nagios XI to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2018-15710?
CVE-2018-15710 affects users of Nagios XI version 5.5.6 that have local authenticated access.
4
What type of vulnerability is CVE-2018-15710?
CVE-2018-15710 is a local privilege escalation vulnerability that can be exploited by authenticated users.
5
When was CVE-2018-15710 disclosed?
CVE-2018-15710 was disclosed in 2018, highlighting a critical security flaw in Nagios XI.