CVE-2019-15949
Summary
| CVE | CVE-2019-15949 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-05 17:15:00 UTC |
| Updated | 2021-04-15 21:16:00 UTC |
| Description | Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root. |
Risk And Classification
EPSS: 0.777410000 probability, percentile 0.995210000 (date 2026-07-22)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Unknown
Problem Types: CWE-78
CISA Known Exploited Vulnerability
| Vendor | Nagios |
|---|---|
| Product | Nagios XI |
| Name | Nagios XI Remote Code Execution Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-15949 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - jakgibb/nagiosxi-root-rce-exploit: POC which exploits a vulnerability within Nagios XI (5.6.5) to spawn a root shell | MISC | github.com | Exploit, Third Party Advisory |
| Nagios XI getprofile.sh Remote Command Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Nagios XI Authenticated Remote Command Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.