CVE-2021-37352: Medium severity Nagios Nagios XI vulnerability
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios XIto a version that resolves this vulnerability.Fixed in 5.8.5
Event History
Frequently Asked Questions
What is CVE-2021-37352?
CVE-2021-37352 is an open redirect vulnerability in Nagios XI before version 5.8.5 that could lead to spoofing.
How does the vulnerability in CVE-2021-37352 work?
The vulnerability in CVE-2021-37352 allows an attacker to exploit an open redirect vulnerability in Nagios XI by sending a specially crafted URL to a user and convincing them to click the link, leading to spoofing.
What is the severity of CVE-2021-37352?
The severity of CVE-2021-37352 is medium with a CVSS score of 6.1.
What software is affected by CVE-2021-37352?
Nagios XI versions before 5.8.5 are affected by CVE-2021-37352.
How can I fix CVE-2021-37352?
To fix CVE-2021-37352, users should update Nagios XI to version 5.8.5 or later.