First published: Mon Feb 15 2021(Updated: )
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | =5.7.5 | |
Nagios Nagios XI | ||
=5.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Nagios XI OS Command Injection is a vulnerability in Nagios XI version xi-5.7.5 that allows for OS command injection through improper sanitization of user-controlled input.
CVE-2021-25296 has a severity score of 8.8 (Critical).
Nagios XI version xi-5.7.5 is affected by CVE-2021-25296.
To fix the Nagios XI OS Command Injection vulnerability, update to a version of Nagios XI that is not affected by the vulnerability.
You can find more information about CVE-2021-25296 at the following references: [http://nagios.com](http://nagios.com), [http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Execution.html](http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Execution.html), [http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Execution.html](http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Execution.html).