CVE-2021-25298
KEV PoC ×4moderateAuthenticated OS Command Injection in Nagios XI 5.7.5 Cloud-VM Config Wizard
CISA: Nagios XI OS Command Injection
CVE-2021-25298 is an OS command injection flaw (CWE-78) in Nagios XI version xi-5.7.5, located in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php. Because user-controlled input is not properly sanitized before being passed to the operating system, an authenticated user with low privileges can trigger the flaw with a single crafted HTTP request to the cloud-vm configuration wizard. Successful exploitation results in arbitrary OS command execution on the Nagios XI server, giving the attacker code execution on the monitoring host with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any organization running Nagios XI 5.7.5 is affected, especially deployments whose web interface is reachable by untrusted or low-privileged users. The flaw is in CISA's Known Exploited Vulnerabilities Catalog (added 2022-01-18), has multiple public PoC exploits and a Metasploit module, and EPSS estimates a 75.1% probability of exploitation within 30 days.
What to do: Apply the vendor's update per CISA KEV required action by upgrading Nagios XI from 5.7.5 to a patched release (a version newer than 5.7.5) as soon as possible; as an interim mitigation, restrict access to the Nagios XI web interface, require strong authentication, and disable or remove the cloud-vm configuration wizard if it is unused. Hunt for compromise by reviewing logs for unexpected OS commands spawned by the Nagios XI web process via the cloud-vm wizard endpoint and for anomalous outbound connections from monitoring servers.
| Nagios XI | 5.7.5 (xi-5.7.5) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
- Affected
- Nagios Nagios XI
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- nagios
- Products
- nagios xi
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H