CVE-2021-3193 questions

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
UWBernie
Posts: 16
Joined: Wed Mar 21, 2018 9:30 am

CVE-2021-3193 questions

Post by UWBernie »

I'm hoping to find out anything more about CVE-2021-3193. Specifically:



Were there active exploits that prompted them to release the update, or just POC's?
When did they first learn about the POC's (or exploits)?
What is the evidence to look for if it was exploited on the box?
When was the update released? (One site says 1/21, one says 1/22.)
benjaminsmith
Posts: 5324
Joined: Wed Aug 22, 2018 4:39 pm
Location: saint paul

Re: CVE-2021-3193 questions

Post by benjaminsmith »

Hi,

It was brought to our attention by a customer, the exploit was patched and we filed the corresponding CVE.

If you feel your system has been compromised, please PM me the system profile and we'll review this for you right away. Alternatively, run a top command and look for the avalonsabre process.

Best Regards,
Benjamin
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.

Be sure to check out our Knowledgebase for helpful articles and solutions!
Locked