Vulnerability record · CVE-2023-48085 · published 14 December 2023
CVE-2023-48085: Nagios XI command_test.php remote code execution
Nagios · Nagios Xi
Nagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 base score is 9.8 (critical), reflecting a network-reachable, low-complexity issue with no privileges or user interaction required. Because Nagios XI is a monitoring platform often holding broad access to managed hosts, successful exploitation is high impact.
Description
Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and a very high EPSS score make this a top remediation priority despite no KEV listing.
What it is
Nagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 base score is 9.8 (critical), reflecting a network-reachable, low-complexity issue with no privileges or user interaction required. Because Nagios XI is a monitoring platform often holding broad access to managed hosts, successful exploitation is high impact.
Impact
An unauthenticated network attacker can execute arbitrary code on the Nagios XI server, gaining full control of the monitoring host and potentially pivoting to systems it manages.
Attack surface
Reached over the network via the command_test.php component, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are needed. The description does not detail the exact request or parameter involved.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.75844, 99.5th percentile), indicating elevated likelihood of exploitation. The only references are vendor advisories, so no public exploit code is confirmed by this record.
What to do
- Upgrade Nagios XI to version 5.11.3 or later, which the vendor states fixes the issue.
- If immediate upgrade is not possible, restrict network access to the Nagios XI web interface to trusted management networks only.
- Review and tighten access controls on the command_test.php endpoint and any test/diagnostic functionality.
- Monitor the Nagios XI host for unexpected process execution or outbound connections from the web server.
- Apply the vendor security guidance at nagios.com/products/security.
Detection
- Inspect web server logs for requests to command_test.php, especially from untrusted or unexpected source IPs.
- Alert on child processes spawned by the Nagios XI web server (Apache/PHP) that are not part of normal operation.
- Monitor for new or modified files and unexpected outbound network connections originating from the Nagios XI host.
- Correlate Nagios XI authentication and access logs for anomalous activity around the command test functionality.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.nagios.com/products/security/ | Vendor Advisory |
| https://www.nagios.com/products/security/ | Vendor Advisory |
Track CVE-2023-48085 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-48085), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.