Junglewise Threat Intelligence

CVE-2019-15949: Nagios XI Remote Code Execution Vulnerability

CVE-2019-15949 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Nagios XI. Vendors: Nagios.

Executive brief

Nagios XI allows authenticated remote command execution as root. The getprofile.sh script, executed via sudo without a password, runs the check_plugin executable which can be modified by a user with nagios or admin permissions to inject malicious commands.

Affected products

  • Nagios Nagios XI before 5.6.6

Timeline

  • 2019-09-05: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: Publication date of the advisory provided

Related threats