ZeroHour

CVE-2020-28900

PoC
CVSS 3.1
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

Vendors
nagios
Products
fusion, nagios xi
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news