CVE-2019-9164: XSS
Published Mar 28, 2019
·Updated
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
Affected Software
1 affected component
Nagios Nagios XI<5.5.11
Event History
Mar 28, 2019
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9164?
CVE-2019-9164 is categorized as a high severity vulnerability due to the potential for unauthenticated command execution.
2
How do I fix CVE-2019-9164?
To fix CVE-2019-9164, upgrade Nagios XI to version 5.5.11 or later as it contains the necessary patches.
3
Who is affected by CVE-2019-9164?
CVE-2019-9164 affects authenticated users of Nagios XI versions prior to 5.5.11.
4
What type of vulnerability is CVE-2019-9164?
CVE-2019-9164 is a command injection vulnerability that allows execution of arbitrary commands.
5
Can CVE-2019-9164 be exploited remotely?
Yes, CVE-2019-9164 can be exploited remotely by authenticated users through the autodiscovery job feature.