HTTP: Nagios XI API Key Regeneration Privilege Escalation

This signature detects attempts to exploit a known vulnerability against API component of Nagios XI.Successful exploitation could result in the low privileged user escalating privileges to those of an administrator.

Extended Description

Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.

Affected Products

Nagios nagios_xi

Short Name
HTTP:CVE-2018-15711-PRI-ESC
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
API CVE-2018-15711 Escalation Key Nagios Privilege Regeneration XI
Release Date
03/13/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Nagios

CVSS Score

6.5

Found a potential security threat?