Vulnerability record · CVE-2021-37350 · published 13 August 2021
CVE-2021-37350: Nagios XI Bulk Modifications Tool SQL injection
Nagios · Nagios Xi
Nagios XI before 5.8.5 contains a SQL injection flaw in the Bulk Modifications Tool caused by improper input sanitisation. Because the vulnerable component is network-reachable and the CVSS vector shows no privileges or user interaction required, it is a serious pre-auth style exposure for any internet- or network-exposed XI instance.
Description
Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction required, and a very high EPSS percentile make this a top remediation priority despite no KEV listing.
What it is
Nagios XI before 5.8.5 contains a SQL injection flaw in the Bulk Modifications Tool caused by improper input sanitisation. Because the vulnerable component is network-reachable and the CVSS vector shows no privileges or user interaction required, it is a serious pre-auth style exposure for any internet- or network-exposed XI instance.
Impact
An attacker can inject arbitrary SQL through the Bulk Modifications Tool, potentially reading or modifying the underlying database and, depending on database privileges, compromising the application and its data.
Attack surface
Reached over the network via the Nagios XI web interface Bulk Modifications Tool; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.7925, 99.58th percentile), indicating strong likelihood of exploitation activity. References are only vendor release notes and advisories, with no public exploit tag supplied.
What to do
- Upgrade Nagios XI to 5.8.5 or later, which the vendor change log identifies as the fixed release.
- If immediate upgrade is not possible, restrict access to the Nagios XI web interface and the Bulk Modifications Tool to trusted management networks only.
- Apply input validation and parameterised queries at the application layer if any custom code touches the Bulk Modifications Tool.
- Review database account privileges used by Nagios XI and reduce them to the minimum needed.
- Monitor vendor advisories for any follow-up guidance on this issue.
Detection
- Inspect web server and Nagios XI logs for anomalous requests to Bulk Modifications Tool endpoints containing SQL metacharacters or UNION/OR patterns.
- Alert on unexpected database errors or verbose SQL error responses returned by the Nagios XI interface.
- Baseline and monitor database queries and account activity for unusual reads or writes originating from the Nagios XI application.
- Correlate outbound or lateral connections from the Nagios XI host that are inconsistent with normal monitoring behaviour.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.nagios.com/downloads/nagios-xi/change-log/ | Release NotesVendor Advisory |
| https://www.nagios.com/downloads/nagios-xi/change-log/ | Release NotesVendor Advisory |
Track CVE-2021-37350 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-37350), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.