#VU25848 Permissions, Privileges, and Access Controls in Nagios XI - CVE-2019-15949
Published: March 10, 2020 / Updated: February 20, 2022
Nagios XI
nagios.org
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the getprofile.sh script in Nagios XI is invoked by downloading a system profile
(profile.php?cmd=download) and is executed as root via a passwordless sudo
entry; the script executes check_plugin, which is owned by the nagios
user. . A remote privileged user can inject and execute arbitrary OS commands as root on the affected system .