QID 375928

QID 375928: Nagios XI Multiple Vulnerabilities

Nagios Core is a free and open source computer-software application that monitors systems, networks and infrastructure. Nagios offers monitoring and alerting services for servers, switches, applications and services.

Affected version:
Nagios XI prior to version 5.8.5
Nagios XI Switch Wizard before version 2.5.7
Nagios XI Docker Wizard before version 1.13
Nagios XI WatchGuard before version 1.4.8

QID Detection Logic:(Authenticated)
It will check for vulnerable versions of Nagios Core from the version file.

Successful exploitation of this vulnerability could lead to Remote Code Execution (RCE).

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released the fix. This issue was fixed in version 5.8.5 or above. Please visit here for more information.
    Vendor References

    CVEs related to QID 375928

    Software Advisories
    Advisory ID Software Component Link
    Nagios XI 5.8.5 URL Logo www.nagios.com/downloads/nagios-xi/change-log/