CyberSec.Space Logo
Back to CVE Browser

CVE-2018-17148

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1850%
EPSS Percentile4.24th
PublishedJun 19, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.

Affected Platforms (CPE)

📦
Nagios

Nagios Xi

< 5.5.4

References & Advisories

Related Vulnerabilities