First published: Wed Apr 18 2018(Updated: )
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios | >=5.2.0<5.4.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8733 has a high severity rating due to the potential for unauthenticated attackers to make critical configuration changes.
To fix CVE-2018-8733, upgrade Nagios XI to version 5.4.13 or later.
CVE-2018-8733 affects Nagios XI versions 5.2.x through 5.4.x before 5.4.13.
CVE-2018-8733 can be exploited by any unauthenticated user, making it particularly dangerous.
The impact of CVE-2018-8733 includes the risk of unauthorized configuration changes and the potential for subsequent SQL injection attacks.