PoC Index

CVE-2018-8735

HIGH 9.0EPSS 63.6%

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
63.56% chance of exploitation in the next 30 days, 99th percentile
Published
2018-04-18
Updated
2024-08-05

Metasploit modules (1)

ExploitDB entries (2)

References

Related