CVE-2020-28904: Critical severity nagios fusion vulnerability
Published May 24, 2021
·Updated
Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.
Affected Software
1 affected component
Nagios Fusion<=4.1.8
Event History
May 24, 2021
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-28904.
2
What is the severity of CVE-2020-28904?
The severity of CVE-2020-28904 is critical with a severity value of 9.8.
3
What is the affected software?
The affected software is Nagios Fusion 4.1.8 and earlier.
4
How does CVE-2020-28904 allow for privilege escalation?
CVE-2020-28904 allows for privilege escalation by executing with unnecessary privileges as nagios via installation of a malicious component containing PHP code.
5
How can I fix CVE-2020-28904?
To fix CVE-2020-28904, it is recommended to update to a version later than 4.1.8 of Nagios Fusion.