QID 375516

Date Published: 2021-05-04

QID 375516: Nagios XI 5.7.5 Have Multiple Vulnerabilities

Nagios Core is a free and open source computer-software application that monitors systems, networks and infrastructure. Nagios offers monitoring and alerting services for servers, switches, applications and services.

CVE-2021-25297-An OS command injection as the apache user through variables passed into the Config Wizard.
CVE-2021-25298-An OS command injection as the apache user through variables passed into the Config Wizard.
CVE-2021-25299-XSS vulnerability in the SSH Terminal page.
Affected version:
Version: 5.7.5

QID Detection Logic:(Authenticated)
It will check for vulnerable version of Nagios Core from version file.

Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary OS and files command which may lead to remote code execution.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    The vendor has released the fix. This issue was fixed in version 5.8.0 or above. Please visit here for more information.

    CVEs related to QID 375516

    Software Advisories
    Advisory ID Software Component Link
    Nagios XI URL Logo www.nagios.com/downloads/nagios-xi/change-log/