CVE-2020-22427: High severity nagios xi vulnerability
DISPUTED NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional commands into a request. NOTE: the vendor disputes whether the CVE and its references are actionable because all technical details are omitted, and the only option is to pay for a subscription service where technical details may be disclosed at an unspecified later time.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this NagiosXI vulnerability?
The vulnerability ID for this NagiosXI vulnerability is CVE-2020-22427.
What is the severity level of CVE-2020-22427?
CVE-2020-22427 has a severity level of high.
How does the CVE-2020-22427 vulnerability affect NagiosXI?
The CVE-2020-22427 vulnerability allows an authenticated nagiosadmin user to inject additional commands into a request in NagiosXI.
How can an attacker exploit CVE-2020-22427?
An attacker can exploit CVE-2020-22427 by injecting additional commands into a request as an authenticated nagiosadmin user.
Are there any known fixes for CVE-2020-22427?
Unfortunately, there are no known fixes for CVE-2020-22427 at the moment. It is recommended to follow the vendor's guidance and monitor for any updates or patches.