CVE-2021-25296
Nagios Xi 5.5.6 – 5.7.5
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2021-25296 is a high-severity an unspecified weakness vulnerability in Nagios Nagios Xi. Its CVSS base score is 8.8 (High).
Operationally, ranked in the top 0.6% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
Nagios XI version xi-5.7.5 is affected by an OS command injection vulnerability in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php. The flaw arises from improper sanitization of input supplied by authenticated users in a single HTTP request, allowing arbitrary operating system commands to be executed on the Nagios XI server.
Authenticated attackers with network access can exploit the issue without user interaction to achieve remote code execution, resulting in complete loss of confidentiality, integrity, and availability on the affected server.
Public proof-of-concept code for remote code execution against this version has been released on PacketStorm Security, and additional technical details are hosted in a GitHub repository documenting Nagios XI bugs. Nagios references its versions page and main site for obtaining updated releases.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2021-12196
Vulnerability Data
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios…
more
XI server.
- CWE(s)
- KEV Date Added
- 18 January 2022
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.