Local File Inclusion Vulnerability in Nagios XI Software by Nagios
CVE-2021-37348

7.5HIGH

Key Information:

Vendor

Nagios

Status
Vendor
CVE Published:
13 August 2021

What is CVE-2021-37348?

Nagios XI versions prior to 5.8.5 contain a local file inclusion vulnerability due to improper validation of pathnames in the index.php file. This flaw may allow an attacker to leverage the vulnerability to include arbitrary files from the server, potentially exposing sensitive information or further compromising the system's integrity.

References

EPSS Score

11% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.