First published: Mon May 24 2021(Updated: )
Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Fusion | <=4.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28902 is a command injection vulnerability in Nagios Fusion 4.1.8 and earlier that allows privilege escalation from Apache to root.
CVE-2020-28902 has a severity rating of 9.8 (critical).
Nagios Fusion version 4.1.8 and earlier is affected by CVE-2020-28902.
To fix CVE-2020-28902, it is recommended to update Nagios Fusion to a version that is not affected by the vulnerability.
More information about CVE-2020-28902 can be found in the following references: [Link 1](http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html), [Link 2](https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/), [Link 3](https://www.nagios.com/downloads/nagios-xi/change-log/)