Back
CVE-2018-8733
CRITICAL
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.
Published: Apr 18, 2018
Modified: Jun 17, 2026
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| nagios | nagios_xi | * ≥ 5.2.0 < 5.4.13 |
GitHub Security Advisory GHSA-gmp2-vm3x-mcpx
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x...
References (12)
- https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT Release Notes, Vendor Advisory
- https://blog.redactedsec.net/exploits/2018/04/26/nagios.html Exploit, Technical Description, Third Party Advisory
- https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f Third Party Advisory
- https://www.exploit-db.com/exploits/44560/ Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44969/ Exploit, Third Party Advisory, VDB Entry
- https://www.nagios.com/downloads/nagios-xi/change-log/ Release Notes, Vendor Advisory
- https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT Release Notes, Vendor Advisory
- https://blog.redactedsec.net/exploits/2018/04/26/nagios.html Exploit, Technical Description, Third Party Advisory
- https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f Third Party Advisory
- https://www.exploit-db.com/exploits/44560/ Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44969/ Exploit, Third Party Advisory, VDB Entry
- https://www.nagios.com/downloads/nagios-xi/change-log/ Release Notes, Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
27.51%
Top 2% most likely to be exploited
Threat Score
47.5 / 100
Data Sources
NVD
EPSS
GitHub