PT-2021-7666 · Nagios Xi · Nagios Xi
Published
2021-02-13
·
Updated
2025-11-03
·
CVE-2021-25297
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Nagios XI version xi-5.7.5
Description
The issue is related to the Nagios XI monitoring tool and is caused by the failure to neutralize special elements used in operating system commands. This can be exploited by sending a special HTTP request, allowing an attacker to execute arbitrary commands. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Recommendations
For Nagios XI version xi-5.7.5, consider disabling the
switch.inc.php file or restricting access to the vulnerable configwizards directory until a patch is available. As a temporary workaround, restrict access to the affected HTTP endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Xi