CVE-2021-40345: Command Injection
Published Oct 26, 2021
·Updated
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.
Affected Software
1 affected component
Nagios Nagios XI=5.8.5
Event History
Oct 26, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-40345?
The severity of CVE-2021-40345 is critical with a CVSS score of 7.2.
2
What is the affected software for CVE-2021-40345?
The affected software for CVE-2021-40345 is Nagios XI version 5.8.5.
3
How can an attacker exploit CVE-2021-40345?
An attacker can exploit CVE-2021-40345 by uploading a ZIP file with a command injection in the name of the first file in the archive, allowing them to execute system commands.
4
Is there a fix available for CVE-2021-40345?
Yes, users should update to the latest version of Nagios XI to fix CVE-2021-40345.
5
Where can I find more information about CVE-2021-40345?
More information about CVE-2021-40345 can be found in the references section.