CVE-2020-28901: Command Injection
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmdsubsys.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28901?
CVE-2020-28901 is a command injection vulnerability in Nagios Fusion 4.1.8 and earlier that allows for privilege escalation or code execution as root.
What is the severity of CVE-2020-28901?
The severity of CVE-2020-28901 is critical with a CVSS score of 9.8.
How can I exploit CVE-2020-28901?
We do not provide information or support for exploiting vulnerabilities.
How can I fix CVE-2020-28901?
To fix CVE-2020-28901, upgrade Nagios Fusion to version 4.1.9 or later.
Where can I find more information about CVE-2020-28901?
You can find more information about CVE-2020-28901 at the following references: [Reference 1](http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html), [Reference 2](https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/), [Reference 3](https://www.nagios.com/downloads/nagios-xi/change-log/).