PT-2025-44535 · Nagios Enterprises · Nagios Xi

Published

2013-02-05

·

Updated

2025-11-06

·

CVE-2013-10073

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2012R1.6
Description Nagios XI versions prior to 2012R1.6 contain a shell command injection issue in the Auto-Discovery tool. User-controlled input is passed to a shell without proper sanitization or argument quoting, potentially allowing an authenticated user with access to discovery functionality to execute arbitrary commands with the privileges of the application service. The vulnerable component involves passing user-supplied data to a shell command without sufficient validation. The Auto-Discovery tool is affected.
Recommendations Update Nagios XI to version 2012R1.6 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14473
CVE-2013-10073

Affected Products

Nagios Xi