CVE-2021-25297
Nagios XI OS Command Injection
Record summary
CVE-2021-25297 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template. CISA lists CVE-2021-25297 in KEV.
Description
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Jan 18, 2022 · CISA
- VulnCheck KEV
- Listed · Jun 1, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Nagios XIBrowse Nagios / Nagios XI | CISA | Version data not supplied | |
Proofs of concept
1Catalogued exploits
MetasploitNagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code ExectionMetasploit exploitby Matthew MathurNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHNagios 5.5.6-5.7.5 - Authenticated Remote Command InjectionCVSS 8.8
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Impact
Successful exploitation of this vulnerability allows an authenticated attacker to execute arbitrary commands on the target system.
Remediation
Upgrade Nagios to a version higher than 5.7.5 or apply the provided patch to mitigate the vulnerability.
Source: ProjectDiscovery