Vulnerability Description
An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileges to the root user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nagios | Nagios Xi | 5.8.5 |
Related Weaknesses (CWE)
References
- https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXTRelease NotesVendor Advisory
- https://synacktiv.comNot Applicable
- https://www.synacktiv.com/sites/default/files/2021-10/Nagios_XI_multiple_vulneraExploitThird Party Advisory
- https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXTRelease NotesVendor Advisory
- https://synacktiv.comNot Applicable
- https://www.synacktiv.com/sites/default/files/2021-10/Nagios_XI_multiple_vulneraExploitThird Party Advisory
FAQ
What is CVE-2021-40343?
CVE-2021-40343 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileges to the root user.
How severe is CVE-2021-40343?
CVE-2021-40343 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40343?
Check the references section above for vendor advisories and patch information. Affected products include: Nagios Nagios Xi.