CVE-2021-37347

HIGH

Nagios XI < 5.8.5 - Local Privilege Escalation via getprofile.sh Directory Argument

Title source: llm
STIX 2.1

Description

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.

References (1)

Core 1
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.nagios.com/downloads/nagios-xi/change-log/

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 24.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
nagios/nagios_xi < 5.8.5
Published Aug 13, 2021
Tracked Since Feb 18, 2026