CVE-2021-25296
Nagios XI OS Command Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
YesDecision
Descriptions
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Nagios XI versión xi-5.7.5, esta afectada por una inyección de comandos del Sistema Operativo. La vulnerabilidad se presenta en el archivo /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php debido a un saneamiento inapropiado de la entrada controlada por el usuario autenticado mediante una única petición HTTP, que puede conllevar a una inyección de comandos del el servidor de Nagios XI
Nagios XI version 5.7.5 suffers from a cross site scripting and multiple remote code execution vulnerabilities.
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-18 CVE Reserved
- 2021-02-15 CVE Published
- 2022-01-18 Exploited in Wild
- 2022-02-01 KEV Due Date
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-11-02 EPSS Updated
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://nagios.com | Product | |
http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Execution.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|