Executive brief
Nagios XI version 5.7.5 is vulnerable to OS command injection via the switch.inc.php configuration wizard. An authenticated attacker can execute arbitrary commands on the server by sending a single crafted HTTP request with unsanitized input.
Affected products
- Nagios Nagios XI 5.7.5
Timeline
- 2021-02-18: disclosed: Initial NVD analysis date
- 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog