CVE-2019-15949: Nagios XI Remote Code Execution Vulnerability

Published Sep 5, 2019
·
Updated

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes checkplugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the checkplugin executable and insert malicious commands to execute as root.

Other sources

Nagios XI contains a remote code execution vulnerability in which a user can modify the checkplugin executable and insert malicious commands to execute as root.

CISA

Affected Software

2 affected components
Nagios Nagios XI
Nagios Nagios XI<5.6.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Nagios XI to a version that resolves this vulnerability.

    Fixed in 5.6.6
  2. Configuration

    Remove the passwordless sudo entry that allows getprofile.sh (invoked by profile.php?cmd=download) to be executed as root.

    sudoers passwordless sudo for getprofile.sh = remove
  3. Configuration

    Ensure the check_plugin executable cannot be modified by the nagios user or by web users who can modify plugins (for example, change ownership to root and remove write permissions for the nagios user).

    Nagios XI check_plugin executable ownership/permissions = not writable by nagios user
  4. Configuration

    Revoke or restrict plugin-upload/modify privileges so only trusted administrator accounts that require this capability can modify plugins.

    Nagios XI web interface plugin modification permission = restrict to trusted administrators only
  5. Compensating control

    Restrict access to the Nagios XI web interface and management functionality to trusted IPs or networks (for example via firewall rules, VPN, or network ACLs) to reduce exposure of admin accounts.

Event History

Sep 5, 2019
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 3, 2021
Known Exploited
via CISA·12:00 AM
Apr 8, 2025
Exploit Published
12:00 AM
Oct 7, 58437
Event
11:04 PM

Frequently Asked Questions

1

What is CVE-2019-15949?

CVE-2019-15949 is a vulnerability in Nagios XI that allows remote code execution as root.

2

What is the severity of CVE-2019-15949?

The severity of CVE-2019-15949 is critical with a CVSS score of 8.8.

3

How does CVE-2019-15949 work?

CVE-2019-15949 can be exploited by accessing the server as the nagios user or as the admin user via the web interface to execute arbitrary commands as root.

4

Which versions of Nagios XI are affected by CVE-2019-15949?

Nagios XI versions up to and excluding 5.6.6 are affected by CVE-2019-15949.

5

How can CVE-2019-15949 be fixed?

To fix CVE-2019-15949, users should update to Nagios XI version 5.6.6 or higher.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203