ID:2011 - Exploit for Incorrect default permissions in Nagios XI - CVE-2019-9166

 
Main Vulnerability Database Exploits ID:2011 - Exploit for Incorrect default permissions in Nagios XI - CVE-2019-9166

ID:2011 - Exploit for Incorrect default permissions in Nagios XI - CVE-2019-9166

Published: March 18, 2020


Vulnerability identifier: #VU18157
Vulnerability risk: Low
CVE-ID: CVE-2019-9166
CWE-ID: CWE-276
Exploitation vector: Local access
Vulnerable software:
Nagios XI

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect default permissions for "config.inc.php" and "import_xiconfig.php" files. A local user with access to the system can modify files and execute arbitrary code on the system with root privleges.


Remediation

Install updates from vendor's website.