VYPR
Critical severity9.8NVD Advisory· Published May 24, 2021· Updated Jun 17, 2026

CVE-2020-28900

CVE-2020-28900

Description

Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Nagios/Fusion2 versions
    cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*range: <=4.1.8
    • (no CPE)range: <=4.1.8
  • Nagios/XI2 versions
    cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*range: <=5.7.5
    • (no CPE)range: <=5.7.5
  • Nagios/Fusiondescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.