9.3
CVSSv2

CVE-2018-16145

Published: 05/09/2018 Updated: 03/10/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor prior to 5.3.1 and 5.4.x prior to 5.4.2 invokes a file that can be edited by the nagios user, and would allow malicious users to elevate their privileges to root after a system restart, hence obtaining full control of the appliance.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opsview opsview

Exploits

Opsview Monitor versions 52, 53, and 54 suffer from cross site scripting and multiple remote command execution vulnerabilities ...