Record summary

CVE-2021-25298 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template. CISA lists CVE-2021-25298 in KEV.

Description

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jan 18, 2022 · CISA
VulnCheck KEV
Listed · Jun 1, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

1

Catalogued exploits

MetasploitNagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code ExectionMetasploit exploitby Matthew MathurNot analyzed1 file

Ruby · linked to 3 vulnerabilities

Metasploit

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHNagios XI 5.5.6-5.7.5 - Authenticated Remote Command InjectionCVSS 8.8

Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

Impact

Successful exploitation of this vulnerability allows an authenticated attacker to execute arbitrary commands on the target system.

Remediation

Upgrade Nagios XI to a patched version or apply the vendor-supplied patch to mitigate this vulnerability.

WeaknessesCWE-78
Authorsk0pak4
Template tagscve2021cvepacketstormoastauthenticatedmsfnagiosxircekevnagiosvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:nagios:nagios_xi:5.7.5:*:*:*:*:*:*:*
Shodan: title:"Nagios XI"
Shodan: http.title:"nagios xi"
FOFA: title="nagios xi"
FOFA: app="nagios-xi"
Google: intitle:"nagios xi"

Source: ProjectDiscovery

References

8