High severity7.2NVD Advisory· Published Oct 26, 2021· Updated Jun 17, 2026
CVE-2021-40345
CVE-2021-40345
Description
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Nagios XI/Nagios XIdescription
Patches
Vulnerability mechanics
References
4- github.com/ArianeBlow/NagiosXI-EmersonFI/blob/main/README.mdnvdExploitThird Party Advisory
- www.synacktiv.com/sites/default/files/2021-10/Nagios_XI_multiple_vulnerabilities_0.pdfnvdExploitThird Party Advisory
- assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXTnvdRelease NotesVendor Advisory
- synacktiv.comnvdNot Applicable
News mentions
0No linked articles in our index yet.