CVE-2020-28907

CRITICAL

Nagios Fusion < 4.1.8 - Improper Certificate Validation in Update Package Download

Title source: llm
STIX 2.1

Description

Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0065
EPSS Percentile 71.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-295
Status published
Products (1)
nagios/fusion < 4.1.8
Published May 24, 2021
Tracked Since Feb 18, 2026