OS Command Injection in Nagios XI - CVE-2020-35578
Published: January 13, 2021 / Updated: May 9, 2021
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the Manage Plugins page during a plugin upload. A remote privileged user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Affected software
How to mitigate CVE-2020-35578
Links to Public Exploits and PoC-codes
- Exploit #5368 - Nagios XI Prior to 5.8.0 - Plugins Filename Authenticated Remote Code Exection (May 9, 2021)
- Exploit #5380 - Nagios XI Scanner (May 9, 2021)
- Exploit #5299 - Nagios XI Remote Code Execution (April 16, 2021)
- Exploit #5044 - Nagios XI 5.7.X - Remote Code Exection RCE (Authenticated) (January 19, 2021)