CVE-2019-15949highunder attackCWE-78

CVE-2019-15949

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.8epss 77%
from disclosure to weapon187 days
Published on NVDSep 5
1st PoC+187d
metasploitJul 29
CISA KEV+790d
exploitation probability
77%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
7 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

Nagios XI before version 5.6.6 allows attackers with admin or nagios user access to execute arbitrary commands as root by modifying a plugin file that gets run with elevated privileges. This can lead to complete system compromise.

Technical detail

CWE-78 (OS Command Injection) via unsafe sudo execution in getprofile.sh script. An authenticated user with plugin modification permissions, or the nagios system user, can alter the check_plugin executable to inject malicious commands that execute as root through a passwordless sudo entry when a system profile is downloaded via profile.php?cmd=download.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.