First published: Mon May 24 2021(Updated: )
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Fusion | <=4.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28901 is a command injection vulnerability in Nagios Fusion 4.1.8 and earlier that allows for privilege escalation or code execution as root.
The severity of CVE-2020-28901 is critical with a CVSS score of 9.8.
We do not provide information or support for exploiting vulnerabilities.
To fix CVE-2020-28901, upgrade Nagios Fusion to version 4.1.9 or later.
You can find more information about CVE-2020-28901 at the following references: [Reference 1](http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html), [Reference 2](https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/), [Reference 3](https://www.nagios.com/downloads/nagios-xi/change-log/).