Insecure File Permissions in Nagios XI Impacting Privilege Escalation
CVE-2021-40343

7.8HIGH

Key Information:

Vendor

Nagios

Status
Vendor
CVE Published:
26 October 2021

What is CVE-2021-40343?

In Nagios XI version 5.8.5, a security issue has been identified involving insecure file permissions on the nagios_unbundler.py script. This vulnerability enables the nagios user to gain escalated privileges, potentially granting access to sensitive system functions and data. Addressing this vulnerability is crucial to maintaining the integrity and security of the systems that utilize Nagios XI.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.