CVE-2021-37343

HIGH

Nagios XI Autodiscovery Webshell Upload

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2021-37343. PoCs published by Erik Wynter, Claroty Team82, jbaines-r7, including Metasploit module auxiliary/scanner/http/nagios_xi_scanner.

AI-analyzed exploit summary This Metasploit module scans Nagios XI installations to detect their version and suggests matching exploit modules based on the version number. It requires authentication or a manually provided version to function.

Description

A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.

Exploits (2)

metasploit SCANNER
by Erik Wynter · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/nagios_xi_scanner.rb

This Metasploit module scans Nagios XI installations to detect their version and suggests matching exploit modules based on the version number. It requires authentication or a manually provided version to function.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Nagios XI
Auth required
Prerequisites: valid Nagios XI credentials or a specific version number
mistral-large-3 · analyzed Jun 05, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Claroty Team82, jbaines-r7 · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/nagios_xi_autodiscovery_webshell.rb

This Metasploit module exploits a path traversal vulnerability (CVE-2021-37343) in Nagios XI before 5.8.5 to upload a PHP web shell and execute arbitrary commands as the `www-data` user. It leverages the autodiscovery job feature to write the shell to a traversed path and then uses it to establish a reverse shell or Meterpreter session.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nagios XI < 5.8.5
Auth required
Prerequisites: Valid Nagios XI administrator credentials · Network access to the Nagios XI web interface
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.nagios.com/downloads/nagios-xi/change-log/
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/165978/Nagios-XI-Autodiscovery-Shell-Upload.html

Scores

CVSS v3 8.8
EPSS 0.2382
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
nagios/nagios_xi < 5.8.5
Published Aug 13, 2021
Tracked Since Feb 18, 2026