First published: Fri Aug 13 2021(Updated: )
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | <5.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37343 is a path traversal vulnerability in Nagios XI below version 5.8.5 AutoDiscovery component, which could lead to post-authenticated remote code execution (RCE) under the security context of the user running Nagios.
The severity of CVE-2021-37343 is high, with a CVSS score of 8.8.
Nagios XI versions below 5.8.5 are affected by CVE-2021-37343.
CVE-2021-37343 can be exploited through a path traversal vulnerability in the AutoDiscovery component of Nagios XI, which allows an attacker to execute remote code under the security context of the Nagios user.
Yes, the vulnerability can be fixed by updating Nagios XI to version 5.8.5 or above.