First published: Mon Jan 04 2016(Updated: )
It was found that default configuration for nagios on Fedora is administrative account with user "nagiosadmin" with fixed password "nagiosadmin" and no IP based access restriction. This information is missing in packaged README file. Original report: <a class="bz_bug_link bz_secure " title="" href="show_bug.cgi?id=1295155">https://bugzilla.redhat.com/show_bug.cgi?id=1295155</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora | ||
Nagios |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1295446 is considered high due to the use of default credentials and lack of access restrictions.
To fix REDHAT-BUG-1295446, change the default password for the nagiosadmin account and implement IP-based access controls.
REDHAT-BUG-1295446 affects Nagios on Red Hat Fedora due to its default configuration.
A temporary workaround for REDHAT-BUG-1295446 is to disable the nagios service until the credentials and access controls are properly configured.
It's important to note that the README file for REDHAT-BUG-1295446 does not include information about the default credentials and necessary access restrictions.