CVE-2020-28910: Critical severity nagios xi vulnerability
Published May 24, 2021
·Updated
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.
Affected Software
1 affected component
Nagios Nagios XI<=5.7.5
Event History
May 24, 2021
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-28910.
2
What is the severity level of CVE-2020-28910?
The severity level of CVE-2020-28910 is critical.
3
How does CVE-2020-28910 affect Nagios XI?
CVE-2020-28910 affects Nagios XI versions 5.7.5 and earlier.
4
What is the risk associated with CVE-2020-28910?
CVE-2020-28910 poses a high risk of privilege escalation through the creation of insecurely permissioned temporary directories and mishandling of symlinks in getprofile.sh.
5
Are there any available fixes for CVE-2020-28910?
Yes, updates and patches are available from the Nagios website to fix CVE-2020-28910.