First published: Tue Oct 26 2021(Updated: )
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | =5.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-40345 is critical with a CVSS score of 7.2.
The affected software for CVE-2021-40345 is Nagios XI version 5.8.5.
An attacker can exploit CVE-2021-40345 by uploading a ZIP file with a command injection in the name of the first file in the archive, allowing them to execute system commands.
Yes, users should update to the latest version of Nagios XI to fix CVE-2021-40345.
More information about CVE-2021-40345 can be found in the references section.