Main
Vulnerability Database
Exploits
ID:2011 - Exploit for Incorrect default permissions in Nagios XI - CVE-2019-9166
ID:2011 - Exploit for Incorrect default permissions in Nagios XI - CVE-2019-9166
Published: March 18, 2020
Vulnerability identifier: #VU18157
Vulnerability risk: Low
CVE-ID: CVE-2019-9166
CWE-ID: CWE-276
Exploitation vector: Local access
Vulnerable software:
Nagios XI
Nagios XI
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for "config.inc.php" and "import_xiconfig.php" files. A local user with access to the system can modify files and execute arbitrary code on the system with root privleges.
Remediation
Install updates from vendor's website.