RULE(RULE ID:334257)

Rule General Information
Release Date: 2021-12-06
Rule Name: Nagios XI WatchGuard Wizard Watchguard.inc.php Command Injection Vulnerability (CVE-2021-37346)
Severity:
CVE ID:
Rule Protection Details
Description: Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://www.nagios.com/downloads/nagios-xi/change-log/
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://www.nagios.com/downloads/nagios-xi/change-log/