Skip to content
COOEY

EXPOSURES › CVE-2019-15949

CVE-2019-15949

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-15949 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Nagios XI allowed attackers to modify the check_plugin executable and execute arbitrary commands as root.

An attacker could alter the check_plugin file to run malicious code with root privileges, enabling full system compromise. DIB organizations must ensure Nagios XI is patched and monitored for unauthorized file modifications to prevent remote code execution and maintain compliance with NIST 800-171 controls.

Shame score — A known RCE vulnerability in a widely deployed monitoring tool that allowed root-level code execution via a modifiable executable, indicating a severe lack of input validation and patch management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Nagios XI's RCE flaw allowing root command execution via check_plugin modification is a critical security failure, widely recognized as severe by security authorities.
cooey ↗ severe-fallout -0.80
Nagios XI's RCE vulnerability allowing root execution via check_plugin modification is a critical flaw, severely impacting system integrity and widely condemned by security authorities.
"Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.