Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-14312
HistorySep 11, 2017 - 10:29 p.m.

Design/Logic Flaw

2017-09-1122:29:00
PRIOn knowledge base
www.prio-n.com
5

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.6%

Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account.

CPENameOperatorVersion
nagios_corele4.3.4

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.6%