Local Privilege Escalation in Nagios XI Pre-5.8.5
CVE-2021-37347

7.8HIGH

Key Information:

Vendor

Nagios

Status
Vendor
CVE Published:
13 August 2021

What is CVE-2021-37347?

Nagios XI, prior to version 5.8.5, contains a vulnerability related to local privilege escalation. This issue arises from the 'getprofile.sh' script, which inadequately validates the directory name passed as an argument. This lack of validation may allow an attacker with local access to manipulate sensitive files or execute unauthorized commands, thereby escalating their privileges within the system. It is crucial for users of affected versions to update to the latest release to mitigate potential risks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.