Permissions, Privileges, and Access Controls in Nagios Fusion and Nagios XI - CVE-2020-28906
Published: May 25, 2021
Vulnerability identifier: #VU53521
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28906
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to incorrect file permissions in fusion-sys.cfg / xi-sys.cfg. A remote authenticated attacker can modify files that are included by scripts and gain elevated privileges on the target system.
Affected software
Nagios Fusion
Nagios XI
Nagios XI
How to mitigate CVE-2020-28906
Install updates from vendor's website.
Nagios Fusion - update to 4.1.9
Nagios XI - update to 5.8.0
Nagios XI - update to 5.8.0