Nagios XI < 5.4.13 Component Download Page RCE
Vulnerability Description
Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used unsafe command construction with attacker-controlled input and lacked sufficient validation and output encoding, allowing an authenticated user to inject commands or otherwise execute arbitrary code with the privileges of the application service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25122
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Bjoern Brixner at Telekom Security
References
More from Nagios
View All →Affected Vendor
Nagios
View all reports →