Executive brief
Nagios XI version 5.7.5 is vulnerable to OS command injection via the windowswmi.inc.php file. The flaw exists due to improper sanitization of authenticated user-controlled input in a single HTTP request, allowing remote attackers to execute arbitrary commands on the server.
Affected products
- Nagios Nagios XI 5.7.5
Timeline
- 2021-02-18: disclosed: Initial NIST analysis date
- 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-18: advisory: Publication date listed in advisory
- 2022-01-18: exploited: Confirmed exploited in the wild per CISA KEV entry date