ZeroHour

CVE-2018-17148

CVSS 3.0
9.8 critical
EPSS
4%p89
Published
()
Modified
Description

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.

Vendors
nagios
Products
nagios xi
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.