7.8
CVSSv3

CVE-2017-16834

Published: 16/11/2017 Updated: 03/10/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PNP4Nagios up to and including 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.

Vulnerable Product Search on Vulmon Subscribe to Product

pnp4nagios pnp4nagios

Vendor Advisories

PNP4Nagios through 0626 has /usr/bin/npcd and npcdcfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account ...