Vulnerability Description
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nagios | Nagios Xi | 5.6.9 |
Related Weaknesses (CWE)
References
- https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.htmlExploitThird Party Advisory
- https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.htmlExploitThird Party Advisory
FAQ
What is CVE-2019-20197?
CVE-2019-20197 is a vulnerability with a CVSS score of 8.8 (HIGH). In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
How severe is CVE-2019-20197?
CVE-2019-20197 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20197?
Check the references section above for vendor advisories and patch information. Affected products include: Nagios Nagios Xi.