Description
Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-related processes/scripts executed with excessive privileges, allowing a local attacker with limited system access to abuse file/command execution paths or writable resources to gain elevated privileges.
Problem types
CWE-250 Execution with Unnecessary Privileges
Product status
Any version before 5.5.7
Credits
Daniel Sayk of Telekom Security
References
www.nagios.com/changelog/nagios-xi/
www.vulncheck.com/...-escalation-via-mrtg-graphing-component