CVE-2021-3277: Malicious File Upload
Published Jun 7, 2021
·Updated
Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.
Affected Software
1 affected component
Nagios Nagios XI<=5.7.5
Event History
Jun 7, 2021
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3277.
2
What is the severity of CVE-2021-3277?
The severity of CVE-2021-3277 is high with a severity score of 7.2.
3
What is the affected software?
The affected software is Nagios XI version 5.7.5 and earlier.
4
How does CVE-2021-3277 allow remote code execution?
CVE-2021-3277 allows remote code execution by allowing authenticated admins to upload arbitrary files due to improper validation of the rename functionality in the custom-includes component, which can lead to the execution of uploaded PHP files.
5
Is there a fix available for CVE-2021-3277?
Yes, upgrading Nagios XI to a version beyond 5.7.5 will fix the vulnerability.