CVE-2021-37345High· 7.8▾ TwilightNagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
nagios_xi < 5.8.5Upgrade past the affected range:
nagios_xi 5.8.5Connected by shared product, vendor, weakness, or advisory.
CVE-2021-37223Medium· 6.5Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php
CVE-2024-33775High· 8.8An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
CVE-2021-25298High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection
CVE-2021-25297High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection
CVE-2021-25296High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection
CVE-2021-25299Medium· 6.1Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS)