CVE-2021-37346
9.8
CRITICAL · CVSS 3.1 · EPSS 73.6% (pctl 99)
Patch early
EPSS 73.6% — above the 10% action threshold.
Description
Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 73.59% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-08-13 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| nagios | nagios xi watchguard wizard |
References
→ the Explorer · watch your stack · NVD