PT-2021-22866 · Nagios Xi · Nagios Xi
Arianeblow
·
Published
2021-10-26
·
Updated
2022-11-08
·
CVE-2021-40345
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Nagios XI version 5.8.5
Description
An issue was discovered in the Manage Dashlets section of the Admin panel, where an administrator can upload ZIP files. A command injection, within the name of the first file in the archive, allows an attacker to execute system commands.
Recommendations
For Nagios XI version 5.8.5, consider restricting access to the Manage Dashlets section of the Admin panel to minimize the risk of exploitation. As a temporary workaround, avoid uploading ZIP files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Xi