First published: Fri Aug 13 2021(Updated: )
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | <5.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-37347.
The title of this vulnerability is 'Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.'
The severity of CVE-2021-37347 is high with a severity value of 7.8.
The software affected by this vulnerability is Nagios XI before version 5.8.5.
To fix CVE-2021-37347, you should upgrade Nagios XI to version 5.8.5 or later.