QID 376512

Date Published: 2022-04-06

QID 376512: Nagios XI Switch Wizard Remote Code Execution (RCE) Vulnerability

Nagios Core is a free and open source computer-software application that monitors systems, networks, and infrastructure. This Nagios XI wizard allows you to monitor network switch and router port status and bandwidth.

Affected versions:
Version prior to 2.5.7

QID Detection Logic:(Authenticated)
It to check for vulnerable version of Nagios switch wizard from version file.

Successful exploitation of this vulnerability may allow an authenticated user to remote code execution through improper neutralization of special elements used in an OS command.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has not released any patch for more information visit here

    CVEs related to QID 376512

    Software Advisories
    Advisory ID Software Component Link
    nagiosxi URL Logo www.nagios.com/products/security/