PT-2025-44535 · Nagios Enterprises · Nagios Xi
Published
2013-02-05
·
Updated
2025-11-06
·
CVE-2013-10073
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 2012R1.6
Description
Nagios XI versions prior to 2012R1.6 contain a shell command injection issue in the Auto-Discovery tool. User-controlled input is passed to a shell without proper sanitization or argument quoting, potentially allowing an authenticated user with access to discovery functionality to execute arbitrary commands with the privileges of the application service. The vulnerable component involves passing user-supplied data to a shell command without sufficient validation. The
Auto-Discovery tool is affected.Recommendations
Update Nagios XI to version 2012R1.6 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Xi