openITCOCKPIT Community Edition versions prior to 5.5.2 contains a command injection vulnerability in host attribute handling that allows authenticated users with host management permissions to execute arbitrary operating system commands on the monitoring backend. The flaw occurs because user-supplied host address data is unsanitized when inserted into monitoring command templates executed by Nagios or Icinga through shell processes, enabling remote code execution. The vulnerability carries a HIGH severity rating with a CVSS score of 8.8. It requires network access and low attack complexity, but necessitates valid user credentials with host modification privileges. Successful exploitation results in complete system compromise, including confidentiality, integrity, and availability impacts to the monitoring infrastructure. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and has not been observed in active exploitation. The EPSS score of 0.0038 indicates this is a lower-priority threat relative to the broader vulnerability landscape. Community attention appears limited, suggesting slow adoption or disclosure. Organizations running openITCOCKPIT Community Edition should prioritize upgrading to version 5.5.2 to remediate this authentication-dependent but high-impact risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.5.2CPE matchmatch criteria | cpe:2.3:a:it-novum:openitcockpit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.