AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-17148

CRITICAL · CVSS 9.8 EPSS 3.68%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-06-19 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-17148
Severity
CRITICAL
CVSS
9.8
EPSS
3.68%

Original NVD Description

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.