Vulnerability Description
Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or improperly escaped, allowing an authenticated attacker who can trigger PDF exports to inject shell metacharacters or arguments.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nagios | Nagios Xi | < 5.7.3 |
Related Weaknesses (CWE)
References
- https://www.nagios.com/changelog/nagios-xi/Release Notes
- https://www.vulncheck.com/advisories/nagios-xi-command-injection-in-report-pdf-dThird Party Advisory
FAQ
What is CVE-2020-36867?
CVE-2020-36867 is a vulnerability with a CVSS score of 8.8 (HIGH). Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper tha...
How severe is CVE-2020-36867?
CVE-2020-36867 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36867?
Check the references section above for vendor advisories and patch information. Affected products include: Nagios Nagios Xi.