CVE-2021-37344: Command Injection
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios XI Switch Wizardto a version that resolves this vulnerability.Fixed in 2.5.7
Event History
Frequently Asked Questions
What is the vulnerability ID for this Nagios XI Switch Wizard vulnerability?
The vulnerability ID for this Nagios XI Switch Wizard vulnerability is CVE-2021-37344.
What is the title of this Nagios XI Switch Wizard vulnerability?
The title of this Nagios XI Switch Wizard vulnerability is 'Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).'
How can this vulnerability be exploited?
This vulnerability can be exploited through improper neutralization of special elements used in an OS Command, leading to remote code execution.
What is the severity of CVE-2021-37344?
The severity of CVE-2021-37344 is classified as critical with a CVSS score of 9.8.
How do I fix the Nagios XI Switch Wizard vulnerability?
To fix the Nagios XI Switch Wizard vulnerability, upgrade to version 2.5.7 or a later version.