CVE-2021-40344

HIGH

Nagios XI 5.8.5 - Authenticated Remote Code Execution via Custom Includes File Upload

Title source: llm
STIX 2.1

Description

An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote command execution.

References (3)

Core 3
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT
Not Applicable x_refsource_misc
https://synacktiv.com

Scores

CVSS v3 7.2
EPSS 0.6619
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
nagios/nagios_xi 5.8.5
Published Oct 26, 2021
Tracked Since Feb 18, 2026