Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 8.8epss 77%
from disclosure to weapon187 days
Published on NVDSep 5
1st PoC+187d
metasploitJul 29
CISA KEV+790d
exploitation probability
77%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
7 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03
Apply updates per vendor instructions.
In short
Nagios XI before version 5.6.6 allows attackers with admin or nagios user access to execute arbitrary commands as root by modifying a plugin file that gets run with elevated privileges. This can lead to complete system compromise.
Technical detail
CWE-78 (OS Command Injection) via unsafe sudo execution in getprofile.sh script. An authenticated user with plugin modification permissions, or the nagios system user, can alter the check_plugin executable to inject malicious commands that execute as root through a passwordless sudo entry when a system profile is downloaded via profile.php?cmd=download.
Summary generated and translated by AI from the official description.
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root.