peter bassill · operator
$ cve CVE-2021-37346 JSON

CVE-2021-37346

9.8
CRITICAL · CVSS 3.1 · EPSS 73.6% (pctl 99)

Patch early

EPSS 73.6% — above the 10% action threshold.

Description

Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS73.59% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2021-08-13
Last modified2026-06-17

Affected (1)

VendorProduct
nagiosnagios xi watchguard wizard

References

→ the Explorer  ·  watch your stack  ·  NVD