CISA Known Exploited Vulnerability

CVE-2019-15949

Nagios · Nagios XI

Nagios XI Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Unknown

CISA description

Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.

Required action

Apply updates per vendor instructions.