OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2018-17148

CRITICAL · CVSS 9.8 EPSS 3.68%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-06-19 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable.

CVE
CVE-2018-17148
Severity
CRITICAL
CVSS
9.8
EPSS
3.68%

Original NVD Description

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.

Related CVEs

Other vulnerabilities affecting the same vendor(s)