First published: Mon Feb 15 2021(Updated: )
** DISPUTED ** NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional commands into a request. NOTE: the vendor disputes whether the CVE and its references are actionable because all technical details are omitted, and the only option is to pay for a subscription service where technical details may be disclosed at an unspecified later time.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | =5.6.11 | |
=5.6.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this NagiosXI vulnerability is CVE-2020-22427.
CVE-2020-22427 has a severity level of high.
The CVE-2020-22427 vulnerability allows an authenticated nagiosadmin user to inject additional commands into a request in NagiosXI.
An attacker can exploit CVE-2020-22427 by injecting additional commands into a request as an authenticated nagiosadmin user.
Unfortunately, there are no known fixes for CVE-2020-22427 at the moment. It is recommended to follow the vendor's guidance and monitor for any updates or patches.