First published: Fri Aug 13 2021(Updated: )
Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | <5.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-37351.
The title of this vulnerability is 'Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.'
The severity of CVE-2021-37351 is medium (5.3).
Nagios XI before version 5.8.5 is affected by CVE-2021-37351.
Unauthenticated users can exploit CVE-2021-37351 by accessing guarded pages through a crafted HTTP request to the server.
Yes, updating Nagios XI to version 5.8.5 or newer will fix CVE-2021-37351.
You can find more information about CVE-2021-37351 on the Nagios XI change log page at https://www.nagios.com/downloads/nagios-xi/change-log/.
The CWE ID for this vulnerability is CWE-276.