First published: Mon May 24 2021(Updated: )
Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges users are able to modify files that can be executed by sudo.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Fusion | <=4.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2020-28909.
CVE-2020-28909 has a severity rating of 8.8 (Critical).
The affected software is Nagios Fusion version 4.1.8 and earlier.
The CWE ID for this vulnerability is CWE-732.
An attacker can exploit CVE-2020-28909 by modifying files that can be executed by sudo, allowing for privilege escalation to root.