Exploitation Summary
CVE-2021-25296 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 18, 2022.
EIP tracks 1 public exploit from researchers including Matthew Mathur, including a Metasploit module exploits/linux/http/nagios_xi_configwizards_authenticated_rce.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits CVE-2021-25296, CVE-2021-25297, and CVE-2021-25298, which are OS command injection vulnerabilities in Nagios XI's configuration wizards. It allows authenticated users to execute arbitrary commands on vulnerable Nagios XI versions (5.5.6 to 5.7.5).
Description
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Exploits (1)
This Metasploit module exploits CVE-2021-25296, CVE-2021-25297, and CVE-2021-25298, which are OS command injection vulnerabilities in Nagios XI's configuration wizards. It allows authenticated users to execute arbitrary commands on vulnerable Nagios XI versions (5.5.6 to 5.7.5).
Nuclei Templates (1)
title:"Nagios XI" || http.title:"nagios xi"
title="nagios xi" || app="nagios-xi"
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H