A chain of vulnerabilities in Nagios XI 5.5.10 allowed a remote attacker to gain a root shell by combining a reflected cross-site scripting flaw, an authenticated remote code execution bug, and a local privilege escalation issue. The attack began with a malicious URL targeting the xiwindow parameter; if an authenticated Nagios XI user with autodiscovery job creation privileges visited the link, the attacker could execute commands as apache:nagios through command injection in autodiscovery job handling via the system_dns parameter.
The final step abused the root-runnable repair_databases.sh script, which evaluated PHP-derived output from a writable configuration file, enabling escalation from the web server context to full root access. The issues were assigned CVE-2019-9164, CVE-2019-9166, and CVE-2019-9167, and Nagios released Nagios XI 5.5.11 to address the initial reported flaw as part of its security disclosures.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The disclosed Nagios XI 5.5.10 issues were assigned CVE-2019-9164, CVE-2019-9166, and CVE-2019-9167. The vulnerabilities covered reflected XSS, authenticated RCE, and local privilege escalation components of the attack chain.
Shielder's disclosure states that Nagios released Nagios XI 5.5.11 to address the first reported issue in a vulnerability chain affecting Nagios XI 5.5.10. The chain included reflected XSS, authenticated remote code execution, and local privilege escalation that could lead to root shell access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.