PT-2021-7666 · Nagios Xi · Nagios Xi

Published

2021-02-13

·

Updated

2025-11-03

·

CVE-2021-25297

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios XI version xi-5.7.5
Description The issue is related to the Nagios XI monitoring tool and is caused by the failure to neutralize special elements used in operating system commands. This can be exploited by sending a special HTTP request, allowing an attacker to execute arbitrary commands. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Recommendations For Nagios XI version xi-5.7.5, consider disabling the switch.inc.php file or restricting access to the vulnerable configwizards directory until a patch is available. As a temporary workaround, restrict access to the affected HTTP endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01123
CVE-2021-25297

Affected Products

Nagios Xi