RULE(RULE ID:335313)

Rule General Information
Release Date: 2021-12-20
Rule Name: Nagios XI Remote Arbitrary Shell Command Injection Vulnerability (CVE-2019-20197)
Severity:
CVE ID:
Rule Protection Details
Description: In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://www.nagios.org/