CVE-2020-28909: Critical severity nagios fusion vulnerability
Published May 24, 2021
·Updated
Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges users are able to modify files that can be executed by sudo.
Affected Software
1 affected component
Nagios Fusion<=4.1.8
Event History
May 24, 2021
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-28909.
2
What is the severity of CVE-2020-28909?
CVE-2020-28909 has a severity rating of 8.8 (Critical).
3
What is the affected software and version?
The affected software is Nagios Fusion version 4.1.8 and earlier.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-732.
5
How can an attacker exploit CVE-2020-28909?
An attacker can exploit CVE-2020-28909 by modifying files that can be executed by sudo, allowing for privilege escalation to root.