CVE-2020-5796: High severity Nagios Nagios XI vulnerability
Published Nov 13, 2020
·Updated
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with root privileges.
Affected Software
1 affected component
Nagios Nagios XI=5.7.4
Event History
Nov 13, 2020
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5796?
CVE-2020-5796 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2020-5796?
To fix CVE-2020-5796, upgrade Nagios XI to version 5.8.0 or later.
3
Who is affected by CVE-2020-5796?
CVE-2020-5796 affects Nagios XI version 5.7.4.
4
What impact does CVE-2020-5796 have on users?
CVE-2020-5796 allows low-privileged authenticated users to escalate privileges and execute arbitrary PHP code.
5
Is there a workaround for CVE-2020-5796?
While immediate patches are recommended, temporary mitigation can be achieved by limiting user permissions and monitoring file changes.