Privilege Escalation and Code Execution in Nagios Fusion and XI Software
CVE-2020-28900
9.8CRITICAL
What is CVE-2020-28900?
A vulnerability in Nagios Fusion and Nagios XI allows an attacker to exploit insufficient verification of data authenticity. This flaw can enable privilege escalation or code execution as root via an untrusted update package processed by the upgrade_to_latest.sh script, exposing systems to potential unauthorized access and control.