Skip to content
COOEY

EXPOSURES › CVE-2021-25297

CVE-2021-25297

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-25297 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Nagios XI suffered an OS command injection vulnerability that allowed attackers to execute arbitrary commands on the server.

Nagios XI contained an OS command injection flaw enabling remote code execution, a critical failure for DIB organizations relying on monitoring infrastructure. The vulnerability was actively exploited in the wild, indicating negligent patching or poor security hygiene. Organizations must ensure Nagios XI is patched to the latest version and restrict command execution capabilities to prevent similar compromises.

Shame score — The vulnerability was actively exploited in the wild, demonstrating a failure to patch known issues and exposing monitoring systems to remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.