VulnerabilityModified
CVE-2021-40345
A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.
HIGH 7.2EPSS 22.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 22.69% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- nagios/nagios xi
- Source
- cve@mitre.org
References
- https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXTRelease Notes, Vendor Advisory
- https://github.com/ArianeBlow/NagiosXI-EmersonFI/blob/main/README.mdExploit, Third Party Advisory
- https://synacktiv.comNot Applicable
- https://www.synacktiv.com/sites/default/files/2021-10/Nagios_XI_multiple_vulnerabilities_0.pdfExploit, Third Party Advisory
- https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXTRelease Notes, Vendor Advisory
- https://github.com/ArianeBlow/NagiosXI-EmersonFI/blob/main/README.mdExploit, Third Party Advisory
- https://synacktiv.comNot Applicable
- https://www.synacktiv.com/sites/default/files/2021-10/Nagios_XI_multiple_vulnerabilities_0.pdfExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.