Description

Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routines using insecure file/command handling and insufficient validation of attacker-controlled inputs, and in some deployments executed with elevated privileges. A local attacker with low-level access could exploit these weaknesses to cause the script to execute arbitrary commands or modify privileged files, resulting in privilege escalation.

INFO

Published Date :

2025-10-30T21:40:03.387Z

Last Modified :

2025-10-31T13:24:59.886Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2020-36868 vulnerability.

Vendors Products
Nagios
  • Nagios Xi
  • Xi
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2020-36868.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact