CVE-2021-25296
HIGH(8.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CVSS 8.8 — Hoch
- EPSS 72% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
72.2%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
8.8
Technische Schwere
SecBoard-Einordnung
CVE-2021-25296 betrifft Nagios XI Version xi-5.7.5 und ist eine OS Command Injection Schwachstelle. Sie befindet sich in der Datei /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php und ermöglicht es einem authentifizierten Benutzer, durch unsachgemäße Bereinigung von Eingaben über eine einzelne HTTP-Anfrage beliebige Betriebssystembefehle auf dem Nagios XI-Server auszuführen. Die Auswirkung ist die vollständige Kompromittierung des Servers. Die Schwachstelle wird aktiv ausgenutzt und ist im CISA KEV-Katalog gelistet, was eine hohe Dringlichkeit signalisiert. Mit einem CVSS-Score von 8.8 (HIGH) und einer EPSS-Wahrscheinlichkeit von 72% für eine Ausnutzung stellt sie ein erhebliches Risiko dar. Security-Teams sollten umgehend alle betroffenen Nagios XI-Instanzen identifizieren und die vom Hersteller bereitgestellten Patches oder Updates anwenden, um die Schwachstelle zu beheben. Eine Priorisierung dieser Maßnahme ist aufgrund der aktiven Ausnutzung und der hohen Kritikalität unerlässlich.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Referenzen
- http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Executio...
- http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Executio...
- https://assets.nagios.com/downloads/nagiosxi/versions.php
- https://github.com/fs0c-sh/nagios-xi-5.7.5-bugs/blob/main/README.md
- https://www.fastly.com/blog/anatomy-of-a-command-injection-cve-2021-25296-7-8-wi...
- http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Executio...
- http://packetstormsecurity.com/files/170924/Nagios-XI-5.7.5-Remote-Code-Executio...
- https://assets.nagios.com/downloads/nagiosxi/versions.php
- https://github.com/fs0c-sh/nagios-xi-5.7.5-bugs/blob/main/README.md
- https://www.fastly.com/blog/anatomy-of-a-command-injection-cve-2021-25296-7-8-wi...