Database/Control plane, storage & DevOps

Nagios XI: OS command injection in the cloud-vm config wizard
CVSS 8.8CVE-2021-25298Control plane, storage & DevOpsKnown exploitedcurated
Impact
OS command injection in the cloud-vm config wizard -> server compromise
Who can reach it
Network (remote)
What to do
Control-plane: upgrade
References
Related entries
- Nagios XI: OS command injection in the windowswmi config wizard (authenticated)CVE-2021-25296 · Nagios XIHigh
- Nagios XI: OS command injection in the switch config wizardCVE-2021-25297 · Nagios XIHigh
- HTCondor (IDTOKENS authentication): A flaw in IDTOKENS lets a user authenticate as another user or as the condorCVE-2021-25312 · HTCondor (IDTOKENS authentication)High
- linuxptp / ptp4l (PTP message forwarding): A missing length check when ptp4l forwards a PTP message between ports leaksCVE-2021-3570 · linuxptp / ptp4l (PTP message forwarding)High
- Terraform Enterprise: Missing authorization on a subset of run-token API requestsCVE-2021-36230 · Terraform EnterpriseHigh
- AMD System Management Mode (SMM) interrupt handler: A flaw in the AMD SMM interrupt handler lets a high-privilegeCVE-2021-39298 · AMD System Management Mode (SMM) interrupt handlerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.