CVE-2021-40344

HIGH

Nagios XI <5.8.5 - RCE

Title source: llm
STIX 2.1

Description

An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote command execution.

References (3)

Core 3
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT
Not Applicable x_refsource_misc
https://synacktiv.com

Scores

CVSS v3 7.2
EPSS 0.6721
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
nagios/nagios_xi 5.8.5
Published Oct 26, 2021
Tracked Since Feb 18, 2026