CVE-2017-14312 is a local privilege escalation vulnerability affecting Nagios Core through version 4.3.4. It arises when the /usr/sbin/nagios executable or nagios.cfg configuration file is owned by a non-root account, despite the initial execution as root. A local attacker with access to this non-root account can exploit this misconfiguration to gain elevated privileges. The vulnerability has a CVSSv3 score of 7.8 (High), indicating high impact on confidentiality, integrity, and availability, with low attack complexity and requiring local access and low privileges. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.3.4CPE matchmatch criteria | cpe:2.3:a:nagios:nagios_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.