RULE(RULE ID:334016)

Rule General Information
Release Date: 2021-10-26
Rule Name: Nagios XI Switch Wizard Remote Code Execution Vulnerability(CVE-2021-37344)
Severity:
CVE ID:
Rule Protection Details
Description: Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: https://www.nagios.com/downloads/nagios-xi/change-log/
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.nagios.com/downloads/nagios-xi/change-log/