PT-2025-44470 · Nagios Enterprises · Nagios Xi
Christian Weiler
·
Published
2025-10-30
·
Updated
2025-10-30
·
CVE-2020-36867
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 5.7.3
Description
Nagios XI versions prior to 5.7.3 contain a command injection issue in the report PDF download/export functionality. Insufficient validation or improper escaping of user-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities allows an authenticated attacker who can trigger PDF exports to inject shell metacharacters or arguments.
Recommendations
Update to version 5.7.3 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Xi