PT-2025-44470 · Nagios Enterprises · Nagios Xi

·

CVE-2020-36867

·

Published

2025-10-30

·

Updated

2025-10-30

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.7.3
Description Nagios XI versions prior to 5.7.3 contain a command injection issue in the report PDF download/export functionality. Insufficient validation or improper escaping of user-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities allows an authenticated attacker who can trigger PDF exports to inject shell metacharacters or arguments.
Recommendations Update to version 5.7.3 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14422
CVE-2020-36867

Affected Products

Nagios Xi