RULE(RULE ID:333537)

Rule General Information
Release Date: 2021-05-13
Rule Name: Nagios XI ajaxhelper Command Injection Vulnerability (CVE-2020-15901)
Severity:
CVE ID:
Rule Protection Details
Description: In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://insinuator.net/2020/07/security-advisories-for-nagios-xi/
https://www.nagios.com/downloads/nagios-xi/change-log/
https://www.nagios.com/products/security/
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://www.nagios.com/downloads/nagios-xi/change-log/