Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Nagios addresses this vulnerability as "Fixed shell vulnerability for autodiscovery tool."
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nagios:nagios_xi:2012:*:*:*:*:*:*:* |
Thu, 06 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios nagios Xi
|
|
| CPEs | cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* cpe:2.3:a:nagios:nagios_xi:2012:r1.0:*:*:*:*:*:* cpe:2.3:a:nagios:nagios_xi:2012:r1.1:*:*:*:*:*:* cpe:2.3:a:nagios:nagios_xi:2012:r1.2:*:*:*:*:*:* cpe:2.3:a:nagios:nagios_xi:2012:r1.3:*:*:*:*:*:* cpe:2.3:a:nagios:nagios_xi:2012:r1.4:*:*:*:*:*:* cpe:2.3:a:nagios:nagios_xi:2012:r1.5:*:*:*:*:*:* |
|
| Vendors & Products |
Nagios nagios Xi
|
|
| Metrics |
cvssV3_1
|
Fri, 31 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios
Nagios xi |
|
| Vendors & Products |
Nagios
Nagios xi |
Thu, 30 Oct 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate sanitation or argument quoting, allowing an authenticated user with access to discovery functionality to execute arbitrary commands with the privileges of the application service. | |
| Title | Nagios XI < 2012R1.6 Auto-Discovery Shell Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-17T18:21:37.775Z
Reserved: 2025-10-28T21:12:09.795Z
Link: CVE-2013-10073
Updated: 2025-10-31T15:02:34.737Z
Status : Analyzed
Published: 2025-10-30T22:15:36.367
Modified: 2025-11-06T16:24:10.723
Link: CVE-2013-10073
No data.
OpenCVE Enrichment
Updated: 2025-10-31T10:13:33Z