HIGH

CVE-2020-22427

CVSS v3

7.2

HIGH

EPSS Score

27.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional commands into a request. NOTE: the vendor disputes whether the CVE and its references are actionable because all technical details are omitted, and the only option is to pay for a subscription service where technical details may be disclosed at an unspecified later time

Technical details

Published
2/15/2021

Frequently asked questions

What is CVE-2020-22427?

NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional commands into a request. NOTE: the vendor disputes whether the CVE and its references are actionable because all technical details are omitted, and the only option is to pay for a subscription service where technical details may be disclosed at an unspecified later time

Is CVE-2020-22427 actively exploited?

Active exploitation of CVE-2020-22427 has not been confirmed. The EPSS score is 27.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-22427?

CVE-2020-22427 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2020-22427 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.