CVE-2020-28910
Nagios XI vulnerability analysis and mitigation

Overview

Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh (Skylight Cyber, Hacker News).

Technical details

The vulnerability exists due to insecure permissions in the getprofile.sh script, which can be executed as sudo from both nagios and apache user contexts. The script reads the last 100 lines of /usr/local/nagiosxi/tmp/phpmailer.log and writes it to /usr/local/nagiosxi/var/components/profile/$folder/phpmailer.log. Since both file locations are writable by the apache user, an attacker can modify the content of phpmailer.log and use symlinks to write data to arbitrary locations, ultimately achieving privilege escalation to root (Skylight Cyber).

Impact

The vulnerability allows a local, low-privileged authenticated user to elevate privileges to root by exploiting the insecure file permissions and symlink handling. This gives the attacker full control over the affected Nagios XI system (GBHackers).

Mitigation and workarounds

The vulnerability was fixed in versions after Nagios XI 5.7.5. Users should upgrade to the latest version to mitigate this security issue (Hacker News).

Community reactions

The vulnerability was part of a larger disclosure of 13 critical vulnerabilities in Nagios products that gained significant attention in the cybersecurity community. Security researchers emphasized that the effort required to find and exploit these vulnerabilities is minimal for sophisticated attackers, particularly nation-states (Skylight Cyber).

Additional resources


SourceThis report was generated using AI

Related Nagios XI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13997CRITICAL9.4
  • Nagios XINagios XI
  • cpe:2.3:a:nagios:nagios_xi
NoNoNov 03, 2025
CVE-2024-13998MEDIUM6
  • Nagios XINagios XI
  • cpe:2.3:a:nagios:nagios_xi
NoNoNov 03, 2025
CVE-2021-47698MEDIUM5.1
  • Nagios XINagios XI
  • cpe:2.3:a:nagios:nagios_xi
NoYesNov 03, 2025
CVE-2024-13992MEDIUM5.1
  • Nagios XINagios XI
  • cpe:2.3:a:nagios:nagios_xi
NoNoOct 31, 2025
CVE-2016-15054N/AN/A
  • Nagios XINagios XI
  • cpe:2.3:a:nagios:nagios_xi
NoYesNov 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management