Junglewise Threat Intelligence

CVE-2021-25297: Nagios XI OS Command Injection

CVE-2021-25297 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-01-18

Technologies: Nagios XI. Vendors: Nagios.

Executive brief

Nagios XI version 5.7.5 is vulnerable to OS command injection via the switch.inc.php configuration wizard. An authenticated attacker can execute arbitrary commands on the server by sending a single crafted HTTP request with unsanitized input.

Affected products

  • Nagios Nagios XI 5.7.5

Timeline

  • 2021-02-18: disclosed: Initial NVD analysis date
  • 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats