Vulnerability record · CVE-2020-35578 · published 13 January 2021
CVE-2020-35578: Nagios XI plugin upload mishandles line endings, allowing OS command execution
Nagios · Nagios Xi
Nagios XI before 5.8.0 mishandles line-ending conversion during plugin upload on the Manage Plugins page, allowing operating-system command injection. A remote, authenticated administrator can turn a plugin upload into arbitrary command execution on the monitoring server. Because Nagios XI is a central monitoring host, compromise has broad reach into the environment it watches.
Description
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote command execution with high EPSS and public exploit code, though it requires an authenticated admin account.
What it is
Nagios XI before 5.8.0 mishandles line-ending conversion during plugin upload on the Manage Plugins page, allowing operating-system command injection. A remote, authenticated administrator can turn a plugin upload into arbitrary command execution on the monitoring server. Because Nagios XI is a central monitoring host, compromise has broad reach into the environment it watches.
Impact
An attacker with admin access gains arbitrary OS command execution on the Nagios XI server, with high impact to confidentiality, integrity and availability. From there they can read monitoring credentials, pivot to monitored hosts, or disrupt monitoring.
Attack surface
Reached over the network through the Manage Plugins page; the CVSS vector (AV:N/AC:L/PR:H/UI:N) indicates no user interaction but high privileges are required, so the attacker must already hold an authenticated admin account.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.819, 99.6th percentile) and public Packet Storm exploit write-ups exist, so exploitation is feasible and likely.
What to do
- Upgrade Nagios XI to 5.8.0 or later, which fixes the plugin upload handling.
- Restrict admin accounts on Nagios XI to the minimum necessary and review who holds them.
- Limit network access to the Nagios XI web interface to trusted management networks.
- Audit uploaded plugins and the plugin directory for unexpected or modified files.
Detection
- Monitor the Nagios XI web and audit logs for plugin uploads, especially by unusual admin accounts or at odd times.
- Alert on child processes spawned by the Nagios XI web server or plugin execution paths that run shell commands.
- Watch for new or changed files in the Nagios XI plugin directory and compare against a known baseline.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/160948/Nagios-XI-5.7.x-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/162207/Nagios-XI-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.nagios.com/downloads/nagios-xi/change-log/ | Release NotesVendor Advisory |
| https://www.nagios.com/products/security/ | Vendor Advisory |
| http://packetstormsecurity.com/files/160948/Nagios-XI-5.7.x-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/162207/Nagios-XI-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.nagios.com/downloads/nagios-xi/change-log/ | Release NotesVendor Advisory |
| https://www.nagios.com/products/security/ | Vendor Advisory |
Track CVE-2020-35578 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35578), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.