HIGH KEV
Nagios XI before 5.6.6 allows remote command execution as root
Published Sep 5, 2019 ·Due May 3, 2022
8.8
HIGHCVSS 3.1
EPSS 77.04%
Description
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://packetstormsecurity.com/files/156676/Nagios-XI-Authenticated-Remote-Command-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162158/Nagios-XI-getprofile.sh-Remote-Command-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://github.com/jakgibb/nagiosxi-root-rce-exploit x_refsource_MISCExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-15949 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/156676/Nagios-XI-Authenticated-Remote-Command-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| http://packetstormsecurity.com/files/162158/Nagios-XI-getprofile.sh-Remote-Command-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://github.com/jakgibb/nagiosxi-root-rce-exploit | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-15949 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 5, 2019
Updated Oct 21, 2025
Reserved Sep 5, 2019
Link CVE-2019-15949
CISA Vulnrichment
Updated Feb 4, 2025