First published: Mon Feb 15 2021(Updated: )
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | =5.7.5 | |
Nagios Nagios XI | ||
=5.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25297 is a vulnerability in Nagios XI version xi-5.7.5 that allows for OS command injection.
CVE-2021-25297 is considered critical with a severity rating of 8.8.
Nagios XI version xi-5.7.5 is affected by CVE-2021-25297.
CVE-2021-25297 occurs due to improper sanitization of authenticated user-controlled input in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php.
CVE-2021-25297 can be exploited by sending a specially crafted HTTP request to the affected Nagios XI instance, allowing for the execution of arbitrary OS commands.