CVE-2020-35578: OS Command Injection
Published Jan 13, 2021
·Updated
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.
Affected Software
1 affected component
Nagios Nagios XI<5.8.0
Event History
Jan 13, 2021
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2020-35578.
2
What is the severity level of CVE-2020-35578?
CVE-2020-35578 has a severity level of critical.
3
What is the affected software version of CVE-2020-35578?
CVE-2020-35578 affects Nagios XI versions up to but excluding 5.8.0.
4
What is the CWE ID associated with CVE-2020-35578?
The CWE ID associated with CVE-2020-35578 is CWE-78.
5
How can a remote admin user exploit CVE-2020-35578?
A remote, authenticated admin user can exploit CVE-2020-35578 by uploading a plugin with mishandled line-ending conversion feature, allowing them to execute operating-system commands.