Nagios XI
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*
- < 2024R1.2
A command injection vulnerability has been identified in Nagios XI versions prior to 2024R1.2, specifically within the Docker Wizard. This vulnerability arises from inadequate validation of user input, which allows authenticated administrators to inject shell metacharacters. These injected characters are then executed as commands on the server, with the same privileges as the Nagios XI web application user. This exploitation could lead to unauthorized command execution on the server.
Exploitation of this vulnerability allows for arbitrary command execution on the server, with the privileges of the Nagios XI web application user.
To reproduce this vulnerability, an authenticated administrator can navigate to the Docker Wizard in Nagios XI. Once there, they can inject shell metacharacters into user input fields. After submitting the input, the injected commands will be executed on the server, demonstrating the command injection vulnerability.
Users can upgrade to Nagios XI version 2024R1.2 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.