← Vulnerability feed

Vulnerability record · CVE-2023-48085 · published 14 December 2023

CVE-2023-48085: Nagios XI command_test.php remote code execution

Nagios · Nagios Xi

Nagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 base score is 9.8 (critical), reflecting a network-reachable, low-complexity issue with no privileges or user interaction required. Because Nagios XI is a monitoring platform often holding broad access to managed hosts, successful exploitation is high impact.

9.8 CVSS 3.1 Critical EPSS 76% · top 0.5% CWE-94 · Code injection
9.8CVSS 3.1 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required and a very high EPSS score make this a top remediation priority despite no KEV listing.

What it is

Nagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 base score is 9.8 (critical), reflecting a network-reachable, low-complexity issue with no privileges or user interaction required. Because Nagios XI is a monitoring platform often holding broad access to managed hosts, successful exploitation is high impact.

Impact

An unauthenticated network attacker can execute arbitrary code on the Nagios XI server, gaining full control of the monitoring host and potentially pivoting to systems it manages.

Attack surface

Reached over the network via the command_test.php component, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are needed. The description does not detail the exact request or parameter involved.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.75844, 99.5th percentile), indicating elevated likelihood of exploitation. The only references are vendor advisories, so no public exploit code is confirmed by this record.

What to do

  • Upgrade Nagios XI to version 5.11.3 or later, which the vendor states fixes the issue.
  • If immediate upgrade is not possible, restrict network access to the Nagios XI web interface to trusted management networks only.
  • Review and tighten access controls on the command_test.php endpoint and any test/diagnostic functionality.
  • Monitor the Nagios XI host for unexpected process execution or outbound connections from the web server.
  • Apply the vendor security guidance at nagios.com/products/security.

Detection

  • Inspect web server logs for requests to command_test.php, especially from untrusted or unexpected source IPs.
  • Alert on child processes spawned by the Nagios XI web server (Apache/PHP) that are not part of normal operation.
  • Monitor for new or modified files and unexpected outbound network connections originating from the Nagios XI host.
  • Correlate Nagios XI authentication and access logs for anomalous activity around the command test functionality.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-48085 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-25296Nagios XI Windows WMI Config Wizard OS Command InjectionNagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected …KEVEPSS 72%analysed8.8CVE-2021-25297Nagios XI switch config wizard OS command injectionNagios XI 5.7.5 fails to sanitize authenticated user input in the switch configuration wizard file switch.inc.php, allowing OS command injection via …KEVEPSS 57%analysed8.8CVE-2021-25298Nagios XI cloud-vm config wizard OS command injectionNagios XI 5.7.5 fails to properly sanitize authenticated user input in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, all…KEVEPSS 75%analysed8.8CVE-2019-15949Nagios XI getprofile.sh command injection allows root code executionNagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that scri…KEVEPSS 77%analysed9.8CVE-2024-24401Nagios XI monitoringwizard.php SQL injection allows remote code executionNagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to a…EPSS 46%analysed9.8CVE-2024-24402Nagios xi improper privilege management vulnerabilityAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.EPSS 3.4%9.8CVE-2023-48084Nagios xi sql injection vulnerabilityNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.EPSS 34%9.8CVE-2022-38250Nagios xi sql injection vulnerabilityNagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2023-48085), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.