Vulnerability record · CVE-2020-5792 · published 20 October 2020
CVE-2020-5792: Nagios XI argument injection enables arbitrary file write and code execution
Nagios · Nagios Xi
Nagios XI 5.7.3 fails to neutralize argument delimiters in a command, allowing an authenticated admin to inject arguments. This lets the attacker write to arbitrary files and ultimately execute code as the apache user.
Description
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with high confidentiality, integrity and availability impact, public exploit code, and very high EPSS, though exploitation requires an authenticated admin account.
What it is
Nagios XI 5.7.3 fails to neutralize argument delimiters in a command, allowing an authenticated admin to inject arguments. This lets the attacker write to arbitrary files and ultimately execute code as the apache user.
Impact
An attacker gains arbitrary file write and remote code execution with the privileges of the apache user. This can lead to full compromise of the Nagios XI host and any data or credentials it holds.
Attack surface
Reachable over the network via the Nagios XI web interface; the CVSS vector requires high privileges (PR:H) and no user interaction (UI:N). The attacker must already hold an authenticated admin account.
Exploitation
Public exploit code is referenced by Packet Storm and Tenable, and EPSS is 0.60966 (99.1st percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV and no ransomware groups are documented using it.
What to do
- Upgrade Nagios XI to a version later than 5.7.3 that fixes the argument injection.
- Restrict admin accounts to the minimum necessary personnel and enforce strong authentication.
- Limit network exposure of the Nagios XI web interface to trusted management networks.
- Monitor and audit admin-level actions for unexpected command or file operations.
Detection
- Review Nagios XI web server and application logs for admin requests containing shell metacharacters or unexpected argument delimiters.
- Monitor for new or modified files in web-accessible directories and other paths writable by the apache user.
- Alert on child processes spawned by the Nagios XI web server (apache) that are not part of normal operation.
- Track use of admin accounts outside normal working hours or from unusual source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162284/Nagios-XI-5.7.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2020-58 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/162284/Nagios-XI-5.7.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2020-58 | ExploitThird Party Advisory |
Track CVE-2020-5792 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5792), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.