CVE-2020-5792
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 61%
from disclosure to weapon0 days
Published on NVDOct 20
metasploitOct 20
exploitation probability
61%top 1% of all CVEs
observed exploitation
nono source reports it
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.
Affected products
n/a · Nagios XI