peter bassill · operator
$ cve CVE-2021-37344 JSON

CVE-2021-37344

9.8
CRITICAL · CVSS 3.1 · EPSS 96.8% (pctl 100)

Patch early

EPSS 96.8% — above the 10% action threshold.

Description

Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS96.77% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2021-08-13
Last modified2026-06-17

Affected (1)

VendorProduct
nagiosnagios xi switch wizard

References

→ the Explorer  ·  watch your stack  ·  NVD