CVE-2018-17148
9.8
CRITICAL · CVSS 3.0 · EPSS 3.7% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.68% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-06-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| nagios | nagios xi |
References
→ the Explorer · watch your stack · NVD