CVE-2021-37346
CRITICALNagios XI WatchGuard Wizard < 1.4.8 - Remote Code Execution via OS Command Injection
Title source: llmDescription
Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).
References (1)
Core 1
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.nagios.com/downloads/nagios-xi/change-log/
Scores
CVSS v3
9.8
EPSS
0.5464
EPSS Percentile
98.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (1)
nagios/nagios_xi_watchguard_wizard
< 1.4.8
Published
Aug 13, 2021
Tracked Since
Feb 18, 2026