CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable.
CVE
CVE-2018-17148
Severity
CRITICAL
CVSS
9.8
EPSS
3.68%
Original NVD Description
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.
Related CVEs
Other vulnerabilities affecting the same vendor(s)