SB2019090521 - Privilege escalation in Nagios XI



SB2019090521 - Privilege escalation in Nagios XI

Published: September 5, 2019 Updated: March 10, 2020

Security Bulletin ID SB2019090521
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-15949)

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to the getprofile.sh script in Nagios XI is invoked by downloading a system profile (profile.php?cmd=download) and is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. . A remote privileged user can inject and execute arbitrary OS commands as root on the affected system .


Remediation

Install update from vendor's website.