Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5791

79
FAUCET Score

CVE-2020-5791 describes an OS command injection vulnerability in Nagios XI versions up to 5.7.3. This flaw allows a remote, authenticated administrator to execute arbitrary operating system commands with the privileges of the apache user. Rated with a CVSS score of 7.2 (HIGH), the vulnerability has a high impact on confidentiality, integrity, and availability, requiring high privileges but no user interaction. While not currently on CISA's KEV catalog, public exploit modules exist in Metasploit and ExploitDB, indicating readily available exploit code, though there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.6.0, <= 5.7.3CPE matchmatch criteria
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
78.63%
Probability of exploitation in next 30 days
EPSS Percentile
99.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Nagios XI 5.6.0-5.7.3 - Mibs.php Authenticated Remote Code Exection · Oct 20, 2020
ExploitDB: EDB-48959 · Oct 28, 2020
This CVE's current EPSS score of 0.7863 is in the 99th percentile among its peer group of 5,537 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (7)

esetvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
mariadbvendor investigatingvia llm_extracted
omronvendor investigatingvia llm_extracted
openrefinevendor investigatingvia llm_extracted
pnpmvendor investigatingvia llm_extracted
twiliovendor investigatingvia llm_extracted

Vendor Advisories (7)

twiliollm-twilio-68bc256e386173e8MEDIUM

Nagios XI Multiple Vulnerabilities

Oct 20, 2020
esetllm-eset-a02d8ec0b42e050eMEDIUM

Nagios XI Multiple Vulnerabilities

Oct 20, 2020
hyperledgerllm-hyperledger-75ca278655c39e7cMEDIUM

Nagios XI Multiple Vulnerabilities

Oct 20, 2020
pnpmllm-pnpm-60fb038873f0764dMEDIUM

Nagios XI Multiple Vulnerabilities

Oct 20, 2020
omronllm-omron-feb7b627ff05f5a4MEDIUM

Nagios XI Multiple Vulnerabilities

Oct 20, 2020
openrefinellm-openrefine-b0c8db1cf4a7c124MEDIUM

Nagios XI Multiple Vulnerabilities

Oct 20, 2020
mariadbllm-mariadb-c9cd0ca51a545b80MEDIUM

Nagios XI Multiple Vulnerabilities

Oct 20, 2020

References

packetstormsecurity.com / files/159743/Nagios-XI-5.7.3-Remote-Command-Injection.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/162235/Nagios-XI-5.7.3-Remote-Code-Execution.html
ExploitThird Party AdvisoryVDB Entry
tenable.com / security/research/tra-2020-58
ExploitThird Party Advisory