First published: Thu Feb 25 2021(Updated: )
Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | <5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Nagios XI vulnerability is CVE-2021-3273.
CVE-2021-3273 has a severity level of critical, with a CVSS score of 7.2.
Nagios XI versions below 5.7 are affected by CVE-2021-3273.
Exploiting CVE-2021-3273 allows an attacker with an admin user account to inject malicious code into the /nagiosxi/admin/graphtemplates.php component of Nagios XI.
To mitigate CVE-2021-3273, it is recommended to update Nagios XI to version 5.7 or higher.