Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate sanitation or argument quoting, allowing an authenticated user with access to discovery functionality to execute arbitrary commands with the privileges of the application service.
2025-10-30T22:15:36.367
2025-11-06T16:24:10.723
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | nagios | nagios_xi | < 2012 | Yes |
| Application | nagios | nagios_xi | 2012 | Yes |
| Application | nagios | nagios_xi | 2012 | Yes |
| Application | nagios | nagios_xi | 2012 | Yes |
| Application | nagios | nagios_xi | 2012 | Yes |
| Application | nagios | nagios_xi | 2012 | Yes |
| Application | nagios | nagios_xi | 2012 | Yes |