← Back to browse
·
API
CVE-2021-25296
Severity
HIGH
CVSS
8.8
EPSS
0.71536
Risk score
85.24
CISA KEV
Yes
PoC
No
Published
2022-01-18
Modified
2022-01-18
First seen
2026-08-05
Aliases
EUVD-2021-12196, GHSA-8HGR-54HV-7PGC
Products
Nagios:Nagios XI, n/a:n/a n/a, nagios:nagios_xi
Sources
nvd
CVE-2021-25296
euvd
EUVD-2021-12196
cisa.gov
CVE-2021-25296
Description
Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
References
http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Execution.html
http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Execution.html
https://assets.nagios.com/downloads/nagiosxi/versions.php
https://github.com/fs0c-sh/nagios-xi-5.7.5-bugs/blob/main/README.md
https://www.fastly.com/blog/anatomy-of-a-command-injection-cve-2021-25296-7-8-with-metasploit-module-and
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25296
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://nvd.nist.gov/vuln/detail/CVE-2021-25296
https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-12196