EXPOSURES › CVE-2021-25297
CVE-2021-25297
HIGH ⌖ ON CISA KEV · EXPLOITEDNagios XI suffered an OS command injection vulnerability that allowed attackers to execute arbitrary commands on the server.
Nagios XI contained an OS command injection flaw enabling remote code execution, a critical failure for DIB organizations relying on monitoring infrastructure. The vulnerability was actively exploited in the wild, indicating negligent patching or poor security hygiene. Organizations must ensure Nagios XI is patched to the latest version and restrict command execution capabilities to prevent similar compromises.
Shame score — The vulnerability was actively exploited in the wild, demonstrating a failure to patch known issues and exposing monitoring systems to remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.