First published: Fri Aug 13 2021(Updated: )
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios Xi Switch Wizard | <2.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Nagios XI Switch Wizard vulnerability is CVE-2021-37344.
The title of this Nagios XI Switch Wizard vulnerability is 'Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).'
This vulnerability can be exploited through improper neutralization of special elements used in an OS Command, leading to remote code execution.
The severity of CVE-2021-37344 is classified as critical with a CVSS score of 9.8.
To fix the Nagios XI Switch Wizard vulnerability, upgrade to version 2.5.7 or a later version.