Back to Database
Status published
Medium
CVE-2013-3505
The Nagios-App component in GroundWork Monitor Enterprise 6.7.0 allows remote...
Vulnerability Description
The Nagios-App component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to bypass intended access restrictions via a direct request for a (1) log file or (2) configuration file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-3505
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/58410
- https://kb.groundworkopensource.com/display/SUPPORT/SA6.7.0-1+Some+web+components+allow+bypass+of+role+access+controls
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20130308-0_GroundWork_Monitoring_Multiple_critical_vulnerabilities_wo_poc_v10.txt
- http://www.kb.cert.org/vuls/id/345260
More from gwos
View All →CVE-2013-3513
Multiple cross-site request forgery (CSRF) vulnerabilities in the Noma component...
Medium
6.8
CVE-2013-3512
The Cacti component in GroundWork Monitor Enterprise 6.7.0 does not...
Medium
6.5
CVE-2013-3511
Open redirect vulnerability in the NeDi component in GroundWork Monitor...
Medium
5.8
CVE-2013-3510
Multiple SQL injection vulnerabilities in GroundWork Monitor Enterprise 6.7.0 allow...
Medium
6.5
CVE-2013-3509
html/System-NeDi.php in the NeDi component in GroundWork Monitor Enterprise 6.7.0...
Medium
6.5
Affected Vendor
gwos
View all reports →Affected Software
groundwork monitor
Vulnerable Versions:
6.7.0
Timeline
Official Publish:
May 8th, 2013
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.