CVE-2021-36364: Critical severity nagios xi vulnerability
Published Sep 28, 2021
·Updated
Nagios XI before 5.8.5 incorrectly allows backupxi.sh wildcards.
Affected Software
1 affected component
Nagios Nagios XI<5.8.5
Event History
Sep 28, 2021
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36364.
2
What is the severity of CVE-2021-36364?
The severity of CVE-2021-36364 is critical (9.8).
3
How does CVE-2021-36364 affect Nagios XI?
CVE-2021-36364 affects Nagios XI versions before 5.8.5.
4
What is the incorrect behavior in Nagios XI that CVE-2021-36364 exploits?
CVE-2021-36364 exploits the incorrect allowance of wildcards in backup_xi.sh in Nagios XI.
5
How can I fix CVE-2021-36364?
To fix CVE-2021-36364, upgrade Nagios XI to version 5.8.5 or later.