CVE-2021-25296High· 8.8▾ Abyssal⚠ Exploited in the wildPoC availableNagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-control…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 14.4 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Feb 1, 2022
Last analysed / modified upstream
72%
72% → 72%
Metasploit ×1 · Nuclei ×1
Added to the CISA catalog on Jan 18, 2022. Federal remediation due Feb 1, 2022. View catalog ↗
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
nagios_xi >= 5.5.6, <= 5.7.5Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-25298High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection
CVE-2021-25297High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection
CVE-2021-25299Medium· 6.1Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS)
CVE-2021-37223Medium· 6.5Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php
CVE-2021-37345High· 7.8Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
CVE-2024-33775High· 8.8An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.