CVE-2021-3273: Code Injection
Published Feb 25, 2021
·Updated
Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system.
Affected Software
1 affected component
Nagios Nagios XI<5.7
Event History
Feb 25, 2021
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Nagios XI vulnerability?
The vulnerability ID for this Nagios XI vulnerability is CVE-2021-3273.
2
What is the severity level of CVE-2021-3273?
CVE-2021-3273 has a severity level of critical, with a CVSS score of 7.2.
3
Which version of Nagios XI is affected by CVE-2021-3273?
Nagios XI versions below 5.7 are affected by CVE-2021-3273.
4
What is the impact of CVE-2021-3273?
Exploiting CVE-2021-3273 allows an attacker with an admin user account to inject malicious code into the /nagiosxi/admin/graphtemplates.php component of Nagios XI.
5
How can I mitigate the vulnerability in Nagios XI?
To mitigate CVE-2021-3273, it is recommended to update Nagios XI to version 5.7 or higher.