Nagios XI 5.7.5 Remote Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 9 Feb 2023.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits CVE-2021-25296, CVE-2021-25297, and CVE-2021-25298, which are OS command injection vulnerabilities in the windowswmi, switch, and cloud-vm configuration wizards that allow an authenticated user to perform remote code execution on Nagios XI versions 5.5.6 to 5.7.5 as the apache user. Valid credentials for a Nagios XI user are required. This module has been successfully tested against official NagiosXI OVAs versions 5.5.6 through 5.7.5.

    Continue reading...
     

Share This Page

Loading...