CVE-2021-37345: High severity Nagios Nagios XI vulnerability
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios XIto a version that resolves this vulnerability.Fixed in 5.8.5 - Configuration
Update the vulnerable scripts/import behavior so xi-sys.cfg is not imported from the var directory when executed with elevated permissions.
Nagios XI scripts using elevated permissions xi-sys.cfg import source = Do not import xi-sys.cfg from the /var directory for scripts running with elevated permissions
Event History
Frequently Asked Questions
What is the vulnerability ID of Nagios XI?
The vulnerability ID of Nagios XI is CVE-2021-37345.
What is the severity of CVE-2021-37345?
The severity of CVE-2021-37345 is high.
What is the affected software of CVE-2021-37345?
The affected software of CVE-2021-37345 is Nagios XI before version 5.8.5.
What is the CVE reference of CVE-2021-37345?
The CVE reference of CVE-2021-37345 is CVE-2021-37345.
How can I fix the vulnerability CVE-2021-37345?
To fix the vulnerability CVE-2021-37345, you should update Nagios XI to version 5.8.5 or later.