Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Nagios Core / XI Authenticated RCE via Custom-Variable Macro Injection
Vulnerability Description
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or contact is referenced in a shell-executed command line, an authenticated attacker with NRDP access can inject OS commands through the macro value. Exploitation requires a non-default configuration in which a custom variable is defined and referenced in a shell-executed command.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
nagios core 命令注入漏洞
Vulnerability Description
nagios core是Nagios公司开源的一款网络监控软件。 nagios core 4.5.13之前版本和Nagios XI 2026R1.5之前版本存在命令注入漏洞,该漏洞源于自定义变量宏注入问题,可能导致具有Nagios Remote Data Processor (NRDP)访问权限的经过身份验证的攻击者注入操作系统命令,从而执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A