CVE-2021-25296: Nagios XI OS Command Injection
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
Other sources
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Affected Software
Event History
Frequently Asked Questions
What is Nagios XI OS Command Injection?
Nagios XI OS Command Injection is a vulnerability in Nagios XI version xi-5.7.5 that allows for OS command injection through improper sanitization of user-controlled input.
How severe is CVE-2021-25296?
CVE-2021-25296 has a severity score of 8.8 (Critical).
Which software version is affected by CVE-2021-25296?
Nagios XI version xi-5.7.5 is affected by CVE-2021-25296.
How can I fix the Nagios XI OS Command Injection vulnerability?
To fix the Nagios XI OS Command Injection vulnerability, update to a version of Nagios XI that is not affected by the vulnerability.
Where can I find more information about CVE-2021-25296?
You can find more information about CVE-2021-25296 at the following references: [http://nagios.com](http://nagios.com), [http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Execution.html](http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Execution.html), [http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Execution.html](http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Execution.html).