CVE-2020-15901: High severity nagios xi vulnerability
Published Jul 22, 2020
·Updated
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
Affected Software
1 affected component
Nagios Nagios XI<5.7.2
Event History
Jul 22, 2020
CVE Published
via MITRE·09:29 PM
Data Sourced
via MITRE·09:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15901?
CVE-2020-15901 is classified as a high severity vulnerability due to the potential for remote command execution.
2
How do I fix CVE-2020-15901?
To fix CVE-2020-15901, upgrade Nagios XI to version 5.7.3 or later.
3
Who is affected by CVE-2020-15901?
Any user running Nagios XI versions prior to 5.7.3 is affected by CVE-2020-15901.
4
What type of attack does CVE-2020-15901 represent?
CVE-2020-15901 represents a remote code execution attack that can be carried out by authenticated users.
5
What component of Nagios XI is vulnerable in CVE-2020-15901?
The vulnerability in CVE-2020-15901 is found in the ajaxhelper.php component of Nagios XI.