Vulnerability Details CVE-2018-15711
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.317
EPSS Ranking 96.6%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2018-15711
-
cpe:2.3:a:nagios:nagios_xi:5.5.6