First published: Wed Jun 29 2022(Updated: )
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | <=5.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29271 is a vulnerability in Nagios XI through 5.8.5 that allows a read-only Nagios user to schedule downtime for any host/services, potentially disabling all monitoring checks.
CVE-2022-29271 has a severity value of 6.5, indicating a medium-level vulnerability.
Nagios XI versions up to and including 5.8.5 are affected by CVE-2022-29271.
An attacker with read-only Nagios user privileges can exploit CVE-2022-29271 to schedule downtime for any host/services, potentially disabling all monitoring checks.
Yes, you can find references for CVE-2022-29271 in the following links: [Reference 1](https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT), [Reference 2](https://github.com/4LPH4-NL/CVEs), [Reference 3](https://github.com/sT0wn-nl/CVEs/blob/master/README.md#nagios-xi).