PT-2025-44470 · Nagios Enterprises · Nagios Xi

Christian Weiler

·

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2020-36867

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.7.3
Description Nagios XI versions prior to 5.7.3 contain a command injection issue in the report PDF download/export functionality. Insufficient validation or improper escaping of user-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities allows an authenticated attacker who can trigger PDF exports to inject shell metacharacters or arguments.
Recommendations Update to version 5.7.3 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14422
CVE-2020-36867

Affected Products

Nagios Xi