PT-2023-3899 · Unknown · Pnp4Nagios

·

CVE-2023-38349

·

Published

2023-07-09

·

Updated

2023-07-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PNP4Nagios versions 0.6.26 and prior to version 81ebfc5
Description The issue is related to a lack of CSRF protection in the AJAX controller of the PNP4Nagios performance analyzer, which is part of the Nagios network monitoring system. This allows a remote attacker to perform a CSRF attack.
Recommendations For PNP4Nagios version 0.6.26, consider disabling the AJAX controller until a patch is available. For versions prior to 81ebfc5, restrict access to the AJAX controller to minimize the risk of exploitation. As a temporary workaround, avoid using the vulnerable AJAX controller functionality until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04191
CVE-2023-38349

Affected Products

Pnp4Nagios