Vulnerability record · CVE-2018-15708 · published 14 November 2018
CVE-2018-15708: Nagios XI Snoopy component allows unauthenticated remote command execution
Nagios · Nagios Xi
Snoopy 1.0 as bundled in Nagios XI 5.5.6 permits remote unauthenticated attackers to execute arbitrary commands through a crafted HTTP request. The flaw is a command injection reachable without credentials, and public exploit code exists, making it a serious risk for internet-exposed Nagios XI installations.
Description
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code available, and very high EPSS probability make this an urgent patch target.
What it is
Snoopy 1.0 as bundled in Nagios XI 5.5.6 permits remote unauthenticated attackers to execute arbitrary commands through a crafted HTTP request. The flaw is a command injection reachable without credentials, and public exploit code exists, making it a serious risk for internet-exposed Nagios XI installations.
Impact
An attacker gains arbitrary command execution on the Nagios XI host, which typically runs with high privileges and can lead to full server compromise and access to monitored infrastructure credentials.
Attack surface
Reached over the network via a crafted HTTP request to the affected Nagios XI component; the CVSS vector indicates no authentication (PR:N) and no user interaction (UI:N) are required.
Exploitation
Public exploit code is referenced on Exploit-DB, Packet Storm and Tenable, and EPSS is very high (0.894, 99.8th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade Nagios XI to a version that removes or fixes the vulnerable Snoopy 1.0 component, following the vendor's guidance.
- If immediate patching is not possible, restrict network access to the Nagios XI web interface to trusted management networks only.
- Remove or disable the Snoopy component if it is not required for monitoring operations.
- Audit the Nagios XI host for signs of compromise and rotate credentials for accounts and monitored systems it can reach.
Detection
- Monitor Nagios XI web server logs for crafted or anomalous HTTP requests targeting Snoopy-related endpoints.
- Alert on unexpected child processes spawned by the Nagios XI web server or PHP processes.
- Review host telemetry for command execution originating from the Nagios XI service account outside normal monitoring activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/153433/Nagios-XI-Magpie_debug.php-Root-Remote-Code-Execution.html | |
| https://www.exploit-db.com/exploits/46221/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2018-37 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/153433/Nagios-XI-Magpie_debug.php-Root-Remote-Code-Execution.html | |
| https://www.exploit-db.com/exploits/46221/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2018-37 | ExploitThird Party Advisory |
Track CVE-2018-15708 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-15708), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.