CVE-2020-36857
Nagios XI < 5.6.14 Authenticated SQL Injection via SNMP Trap Interface Page
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.6EPSS 2.0%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
30 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could supply crafted input that is not properly sanitized, allowing SQL injection that may lead to unauthorized disclosure or modification of application data or execution of arbitrary SQL commands against the backend database.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Affected products
Nagios · XIWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →