CVE-2018-16145
05.09.2018, 21:29
The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file that can be edited by the nagios user, and would allow attackers to elevate their privileges to root after a system restart, hence obtaining full control of the appliance.Enginsight
Vendor | Product | Version |
---|---|---|
opsview | opsview | 𝑥 < 5.3.1 |
opsview | opsview | 5.4.0 ≤ 𝑥 < 5.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References