RULE(RULE ID:333597)

Rule General Information
Release Date: 2021-06-01
Rule Name: Nagios XI autodiscovery_component_update_cron Command Injection Vulnerability (CVE-2020-28648)
Severity:
CVE ID:
Rule Protection Details
Description: A command injection vulnerability has been reported in Nagios XI. The vulnerability is due to insufficient input validation of the requests submitted to the Auto-Discovery endpoint. A remote authenticated attacker can exploit this vulnerability by sending a crafted request to the server. Successful exploitation could result in arbitrary command execution with privileges of the web server on the target system.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html
https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/
https://www.nagios.com/downloads/nagios-xi/change-log/
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.nagios.com/downloads/nagios-xi/change-log/