PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.
NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.
|CVSS3 Base Score||6.7|
|CVSS3 Base Metrics||CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H|
|Red Hat Gluster Storage 3||pnp4nagios||Not affected|