CVE-2020-28900

CRITICAL

Nagios Fusion < 4.1.8 and Nagios XI < 5.7.5 - Privilege Escalation and Code Execution via Untrusted Update Package

Title source: llm
STIX 2.1

Description

Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0079
EPSS Percentile 74.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-345
Status published
Products (2)
nagios/fusion < 4.1.8
nagios/nagios_xi < 5.7.5
Published May 24, 2021
Tracked Since Feb 18, 2026