VulnerabilityModified
CVE-2016-0726
The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.
CRITICAL 9.8EPSS 2.26%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.26% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- nagios/nagios
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1295446Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1295446Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.