ZeroHour

CVE-2021-25298

KEV PoC ×4moderate

Authenticated OS Command Injection in Nagios XI 5.7.5 Cloud-VM Config Wizard

CISA: Nagios XI OS Command Injection

CVSS 3.1
8.8 high
EPSS
75%p99
Published
()
KEV added
AI analysis

CVE-2021-25298 is an OS command injection flaw (CWE-78) in Nagios XI version xi-5.7.5, located in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php. Because user-controlled input is not properly sanitized before being passed to the operating system, an authenticated user with low privileges can trigger the flaw with a single crafted HTTP request to the cloud-vm configuration wizard. Successful exploitation results in arbitrary OS command execution on the Nagios XI server, giving the attacker code execution on the monitoring host with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any organization running Nagios XI 5.7.5 is affected, especially deployments whose web interface is reachable by untrusted or low-privileged users. The flaw is in CISA's Known Exploited Vulnerabilities Catalog (added 2022-01-18), has multiple public PoC exploits and a Metasploit module, and EPSS estimates a 75.1% probability of exploitation within 30 days.

What to do: Apply the vendor's update per CISA KEV required action by upgrading Nagios XI from 5.7.5 to a patched release (a version newer than 5.7.5) as soon as possible; as an interim mitigation, restrict access to the Nagios XI web interface, require strong authentication, and disable or remove the cloud-vm configuration wizard if it is unused. Hunt for compromise by reviewing logs for unexpected OS commands spawned by the Nagios XI web process via the cloud-vm wizard endpoint and for anomalous outbound connections from monitoring servers.

Affected
Nagios XI5.7.5 (xi-5.7.5)
Estimated exposure
moderateplausibly in the tens of thousands of Nagios XI deployments worldwide, with thousands of instances observed exposed on the public internet (order-of-magnitude… — No vendor-published install count is available, but Nagios XI is a widely deployed enterprise and government infrastructure monitoring platform and public internet scans regularly surface thousands of exposed Nagios XI instances,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

CISA Known Exploited Vulnerability
Affected
Nagios Nagios XI
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
nagios
Products
nagios xi
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news