PT-2021-22866 · Nagios Xi · Nagios Xi

Arianeblow

·

Published

2021-10-26

·

Updated

2022-11-08

·

CVE-2021-40345

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios XI version 5.8.5
Description An issue was discovered in the Manage Dashlets section of the Admin panel, where an administrator can upload ZIP files. A command injection, within the name of the first file in the archive, allows an attacker to execute system commands.
Recommendations For Nagios XI version 5.8.5, consider restricting access to the Manage Dashlets section of the Admin panel to minimize the risk of exploitation. As a temporary workaround, avoid uploading ZIP files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-40345

Affected Products

Nagios Xi