CVE-2021-37348: High severity Nagios Nagios XI vulnerability
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios XIto a version that resolves this vulnerability.Fixed in 5.8.5
Event History
Frequently Asked Questions
What is CVE-2021-37348?
CVE-2021-37348 is a vulnerability found in Nagios XI before version 5.8.5 that allows local file inclusion.
How does CVE-2021-37348 affect Nagios XI?
CVE-2021-37348 affects Nagios XI versions prior to 5.8.5 and can be exploited through improper limitation of a pathname in index.php.
What is the severity of CVE-2021-37348?
The severity of CVE-2021-37348 is high with a CVSS score of 7.5.
How can I fix CVE-2021-37348?
To fix CVE-2021-37348, upgrade Nagios XI to version 5.8.5 or later.
Where can I find more information about CVE-2021-37348?
You can find more information about CVE-2021-37348 in the Nagios XI change log at https://www.nagios.com/downloads/nagios-xi/change-log/