EXPOSURES › CVE-2021-25296
CVE-2021-25296
HIGH ⌖ ON CISA KEV · EXPLOITEDNagios XI suffered an OS command injection vulnerability that allowed attackers to execute arbitrary commands on the server.
Nagios XI contained an OS command injection flaw enabling remote code execution, a critical failure for DIB organizations relying on monitoring infrastructure. The vulnerability was actively exploited in the wild, indicating negligent patching or poor security hygiene. Organizations must ensure Nagios XI is patched to prevent command execution and potential data exfiltration or system compromise.
Shame score — The vulnerability was actively exploited in the wild, demonstrating a failure to patch known issues and exposing monitoring systems to remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.