Vulnerability record · CVE-2020-5791 · published 20 October 2020
CVE-2020-5791: Nagios XI OS command injection in admin interface
Nagios · Nagios Xi
Nagios XI 5.7.3 fails to neutralize special elements used in an OS command, allowing an authenticated administrator to run operating system commands. Because the affected component is the monitoring server itself, successful exploitation gives an attacker a foothold on a host that typically holds broad infrastructure credentials.
Description
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows authenticated remote code execution on a sensitive monitoring host, and public exploit code plus a very high EPSS score make it a realistic target despite the admin privilege requirement.
What it is
Nagios XI 5.7.3 fails to neutralize special elements used in an OS command, allowing an authenticated administrator to run operating system commands. Because the affected component is the monitoring server itself, successful exploitation gives an attacker a foothold on a host that typically holds broad infrastructure credentials.
Impact
An attacker with admin access executes arbitrary OS commands as the apache user, enabling data theft, configuration tampering, or lateral movement from the monitoring server.
Attack surface
Reachable over the network through the Nagios XI web interface; the attacker must already hold an authenticated admin account, and no user interaction is required.
Exploitation
Public exploit code is referenced by Packet Storm and Tenable advisories, and EPSS is very high (0.786, 99.6th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade Nagios XI past 5.7.3 to a vendor-supported release that fixes the command injection.
- Restrict admin accounts to the minimum necessary staff and enforce strong authentication.
- Limit network access to the Nagios XI web interface to trusted management networks.
- Run the Nagios XI web service under a low-privilege account with no unnecessary OS permissions.
- Monitor and review admin account activity and configuration changes for signs of abuse.
Detection
- Alert on unexpected child processes spawned by the Nagios XI web server or apache user.
- Audit Nagios XI admin logins and configuration changes for anomalies or off-hours activity.
- Search web server and application logs for command-injection payload patterns in admin requests.
- Monitor outbound connections from the Nagios XI host to unfamiliar destinations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/159743/Nagios-XI-5.7.3-Remote-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/162235/Nagios-XI-5.7.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2020-58 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/159743/Nagios-XI-5.7.3-Remote-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/162235/Nagios-XI-5.7.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2020-58 | ExploitThird Party Advisory |
Track CVE-2020-5791 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5791), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.