CVE-2019-15949 is a critical remote command execution vulnerability affecting Nagios XI versions prior to 5.6.6. It allows an authenticated attacker (either as an admin via the web interface or as the nagios user on the server) to execute arbitrary commands as root. The vulnerability stems from the getprofile.sh script, which is executed with root privileges and calls the nagios-owned check_plugin, enabling malicious modification. This vulnerability carries a CVSS score of 8.8 (HIGH), indicating a severe risk with low attack complexity and high impact on confidentiality, integrity, and availability. Its EPSS score is exceptionally high, and it has a FAUCET Risk Score of 100/100. CVE-2019-15949 is actively exploited (KEV listed) and has publicly available exploit modules in Metasploit and ExploitDB, confirming its weaponization. Despite its severity and active exploitation, there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.6.6CPE matchmatch criteria | cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.