CVE-2019-3698 - CVE House
Back to Database
Status published Medium CVE-2019-3698

nagios cron job allows privilege escalation from user nagios to root

Vulnerability Description

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-3698

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Matthias Gerstner

Affected Vendor

Affected Software

SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11, Factory
Vulnerable Versions:
nagios

Timeline

Official Publish: February 28th, 2020
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L

Weaknesses (CWE)