Nagios XI exploits

Nagios XI is a large PHP web application, and its breadth has made it a repeated source of serious vulnerabilities across its components: SQL injection in various endpoints, authentication bypasses, and command injection in features that shell out, frequently chained together. A common pattern is an unauthenticated SQL injection or auth bypass that yields an admin session or API key, followed by a command-injection or configuration feature that runs commands on the server, reaching remote code execution and, because XI components run with elevated rights, often root. Many of these are pre-authentication or require only low privilege. The method is to fingerprint the exact XI version and match it to the applicable chain, since the vulnerable component and request are version-specific.

bash
# fingerprint XI version, then match to the advisory/chain
curl -sk https://<target>/nagiosxi/ | grep -ioE 'Nagios XI [0-9.]+'
# the chains are version-specific: e.g. unauth SQLi/auth-bypass to recover an admin
# API key or session, then command injection in a config/tool endpoint for RCE.
# match the XI build to the exploit (Metasploit has several Nagios XI modules).

Exploitation notes#

  • Fingerprint the XI version first; the exploitable component (a specific .php endpoint, API handler, or tool) and whether it is pre-auth are version-specific, so the version maps to the chain.
  • The common shape is access-then-execute: an unauthenticated SQLi or auth bypass for an admin context, then a command-injection or script feature for RCE; identify both halves for the target build.
  • XI components frequently run with high privilege, so successful RCE is often root on the monitoring server, which then holds every monitored host's credentials.
  • Metasploit packages several Nagios XI chains; where none applies, the authenticated command injection route remains.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more