CVE-2020-24899: OS Command Injection
Published Feb 15, 2021
·Updated
Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp query.
Affected Software
1 affected component
Nagios Nagios XI=5.7.2
Event History
Feb 15, 2021
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
Description
Frequently Asked Questions
1
What is CVE-2020-24899?
CVE-2020-24899 refers to a remote code execution (RCE) vulnerability in Nagios XI 5.7.2.
2
How does the CVE-2020-24899 vulnerability affect Nagios XI?
The CVE-2020-24899 vulnerability allows an authenticated user to inject additional commands into the web application query of Nagios XI 5.7.2.
3
Is authentication required to exploit the CVE-2020-24899 vulnerability?
Yes, the CVE-2020-24899 vulnerability requires authentication to exploit.
4
What is the severity of CVE-2020-24899?
The severity of CVE-2020-24899 is rated as high with a CVSS score of 8.8.
5
How can I mitigate the CVE-2020-24899 vulnerability?
To mitigate the CVE-2020-24899 vulnerability, it is recommended to update Nagios XI to a version that contains the necessary security patches.