CVE-2018-16145
The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file that can be edited by the nagios user, and would allow attackers to elevate their privileges to root after a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file that can be edited by the nagios user, and would allow attackers to elevate their privileges to root after a system restart, hence obtaining full control of the appliance.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- opsview/opsview
- Source
- cve@mitre.org
References
- https://knowledge.opsview.com/v5.3/docs/whats-newRelease Notes, Vendor Advisory
- https://knowledge.opsview.com/v5.4/docs/whats-newRelease Notes, Vendor Advisory
- https://seclists.org/fulldisclosure/2018/Sep/3Exploit, Mailing List, Third Party Advisory
- https://www.coresecurity.com/advisories/opsview-monitor-multiple-vulnerabilitiesExploit, Third Party Advisory
- https://knowledge.opsview.com/v5.3/docs/whats-newRelease Notes, Vendor Advisory
- https://knowledge.opsview.com/v5.4/docs/whats-newRelease Notes, Vendor Advisory
- https://seclists.org/fulldisclosure/2018/Sep/3Exploit, Mailing List, Third Party Advisory
- https://www.coresecurity.com/advisories/opsview-monitor-multiple-vulnerabilitiesExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.