Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-12847

20
FAUCET Score

CVE-2017-12847 is a local privilege escalation vulnerability affecting Nagios Core versions prior to 4.3.3. It arises from the creation of a PID file (nagios.lock) after privilege dropping, allowing a local attacker with access to the non-root Nagios account to modify this file. This manipulation could lead to the termination of arbitrary processes when a root script subsequently executes a "kill" command based on the modified PID. The vulnerability has a CVSS score of 6.3 (Medium), indicating high impact on integrity and availability with high attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.3.2CPE matchmatch criteria
cpe:2.3:a:nagios:nagios:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.3MEDIUM

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.2
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.79%
Probability of exploitation in next 30 days
EPSS Percentile
52.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0079 is in the 90th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 6 (Juno)Fixed in: nagios
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)Fixed in: nagios
redhatend of lifevia redhat_api
Product: Red Hat Storage 3Fixed in: nagios

Vendor Advisories (1)

redhatCVE-2017-12847Low

nagios: Incorrect permissions for PID file

Jul 28, 2017

References

github.com / NagiosEnterprises/nagioscore/blob/master/Changelog
Release NotesVendor Advisory
github.com / NagiosEnterprises/nagioscore/commit/1b197346d490df2e2d3b1dcce5ac6134ad0c8752
PatchVendor Advisory
github.com / NagiosEnterprises/nagioscore/commit/3baffa78bafebbbdf9f448890ba5a952ea2d73cb
PatchVendor Advisory
github.com / NagiosEnterprises/nagioscore/issues/404
Issue TrackingVendor Advisory
security.gentoo.org / glsa/201710-20
Third Party Advisory
securityfocus.com / bid/100403
Third Party AdvisoryVDB Entry