ZeroHour

CVE-2020-28910

PoC
CVSS 3.1
9.8 critical
EPSS
4%p90
Published
()
Modified
Description

Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.

Vendors
nagios
Products
nagios xi
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news