PT-2021-4143 · Nagios Xi · Nagios Xi

Published

2021-08-13

·

Updated

2022-07-12

·

CVE-2021-37349

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.8.5
Description The issue is related to insecure privilege management in the clean.php file of the Nagios XI monitoring tool. It allows an attacker to escalate their privileges due to the lack of input sanitization from the database.
Recommendations For versions prior to 5.8.5, update to version 5.8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the cleaner.php file until a patch is applied.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04736
CVE-2021-37349

Affected Products

Nagios Xi