S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25298 Scanner

CVE-2021-25298 scanner - OS Command Injection vulnerability in Nagios XI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-25298
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Nagios XI is a popular IT infrastructure monitoring tool used by organizations to keep track of their IT systems. The software is designed to monitor servers, switches, applications, and services, and provide alerts to system admins when any issues arise. Nagios XI helps organizations ensure that their systems are running smoothly and efficiently, and that any potential problems can be addressed before they cause serious damage.

However, Nagios XI version xi-5.7.5 has been found to have a serious vulnerability, identified as CVE-2021-25298. This vulnerability can potentially allow an attacker to inject malicious code into the Nagios XI server, which can then compromise the entire IT infrastructure of the organization. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, due to inadequate sanitization of user-controlled input. This means that any authenticated user can execute unauthorized commands on the Nagios XI server, leading to OS command injection.

The exploitation of this vulnerability can be quite dangerous for organizations, as attackers can gain complete control over the IT infrastructure of the organization. Attackers can potentially steal sensitive data, install malicious software, or cause service disruptions to the organization's systems. Therefore, it is crucial for organizations to take immediate action to mitigate the risk of this vulnerability.

In conclusion, it's important for organizations to be aware of the potential risks associated with Nagios XI's CVE-2021-25298 vulnerability and take appropriate measures to protect their IT infrastructure. With the pro features of the s4e.io platform, organizations can easily and quickly learn about vulnerabilities in their digital assets and take action to mitigate any risks. By prioritizing security, organizations can ensure that their IT systems are protected from potential threats.

 

REFERENCES

Solution Advice

The following precautions can be taken to protect against this vulnerability:

  • Upgrade Nagios XI to the latest version, which has addressed the CVE-2021-25298 vulnerability.
  • Make sure to sanitize all user-controlled input before processing it on the Nagios XI server.
  • Limit the permissions of Nagios XI users to minimize the potential damage of any exploit.
  • Regularly scan the Nagios XI system for vulnerabilities and take proactive measures to address any issues.
  • Implement security measures such as firewalls, intrusion detection systems, and strong passwords to protect the Nagios XI server from external attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.