vendor:
Nagios Core
by:
Dawid Golunski
9,8
CVSS
CRITICAL
Privilege Escalation
264
CWE
Product Name: Nagios Core
Affected Version From: < 4.2.4
Affected Version To: < 4.2.4
Patch Exists: YES
Related CWE: CVE-2016-9566, CVE-2016-9565
CPE: a:nagios:nagios_core
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-usn-3253-2/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2016-9565/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-9565/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2016
Nagios Core < 4.2.4 Root Privilege Escalation PoC Exploit
This PoC exploit allows privilege escalation from 'nagios' system account, or an account belonging to 'nagios' group, to root (root shell). Attackers could obtain such an account via exploiting another vulnerability, e.g. CVE-2016-9565 linked below.
Mitigation:
Update to Nagios Core version 4.2.4 or later.