VulnerabilityModified
CVE-2021-37344
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).
CRITICAL 9.8EPSS 96.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 96.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 96.77% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- nagios/nagios xi switch wizard
- Source
- cve@mitre.org
References
- https://www.nagios.com/downloads/nagios-xi/change-log/Release Notes, Vendor Advisory
- https://www.nagios.com/downloads/nagios-xi/change-log/Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.