HIGH

CVE-2021-25296

Nagios Nagios Xi 2021-02-15 CVSS v3.1
CVSS
8.8
KEV

Description

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Summary dbcve.org

Nagios XI xi-5.7.5 contains an OS command injection vulnerability in the Windows WMI configuration wizard (windowswmi.inc.php). Authenticated users can inject arbitrary OS commands through unsanitized user input in a single HTTP request, leading to complete compromise of the Nagios XI server.

Mitigation

Upgrade to Nagios XI version 5.8.0 or later which contains the patched version of windowswmi.inc.php with proper input sanitization. If immediate patching is not possible, restrict access to the Windows WMI configuration wizard to only trusted administrators.

Proof of Concept

EPSS Score

72.18%
Probability of exploitation in next 30 days
99.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE