Exploitation Summary
EIP tracks 2 public exploits for CVE-2021-37343.
PoCs published by Erik Wynter, Claroty Team82, jbaines-r7, including Metasploit module auxiliary/scanner/http/nagios_xi_scanner.
AI-analyzed exploit summary This Metasploit module scans Nagios XI installations to detect their version and suggests matching exploit modules based on the version number. It requires authentication or a manually provided version to function.
Description
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.
Exploits (2)
This Metasploit module scans Nagios XI installations to detect their version and suggests matching exploit modules based on the version number. It requires authentication or a manually provided version to function.
This Metasploit module exploits a path traversal vulnerability (CVE-2021-37343) in Nagios XI before 5.8.5 to upload a PHP web shell and execute arbitrary commands as the `www-data` user. It leverages the autodiscovery job feature to write the shell to a traversed path and then uses it to establish a reverse shell or Meterpreter session.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H