HTTP: Nagios XI Multiple SQL Injection

This signature detects attempts to exploit a known vulnerability against Nagios XI. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.

Affected Products

Nagios nagios_xi

Short Name
HTTP:SQL:NAGIOS-XI-SNMP-SQLINJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2021-37350 Injection Multiple Nagios SQL XI
Release Date
11/18/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3781
False Positive
Unknown
Vendors

Nagios

CVSS Score

7.5

Found a potential security threat?