CVE-2020-15903: Critical severity nagios xi vulnerability
Published Sep 9, 2020
·Updated
An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was fixed in version 5.7.3.
Affected Software
1 affected component
Nagios Nagios XI<5.7.3
Event History
Sep 9, 2020
CVE Published
via MITRE·08:29 PM
Data Sourced
via MITRE·08:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15903?
CVE-2020-15903 is considered a medium severity privilege escalation vulnerability in Nagios XI.
2
How do I fix CVE-2020-15903?
To fix CVE-2020-15903, upgrade Nagios XI to version 5.7.3 or later.
3
Which versions of Nagios XI are affected by CVE-2020-15903?
Nagios XI versions prior to 5.7.3 are affected by CVE-2020-15903.
4
What is the nature of the vulnerability described in CVE-2020-15903?
CVE-2020-15903 is a privilege escalation vulnerability that allows the nagios user to edit certain files running as root.
5
When was CVE-2020-15903 first disclosed?
CVE-2020-15903 was disclosed as part of a security advisory related to Nagios XI prior to its resolution in version 5.7.3.