{"id":"CVE-2021-37344","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-37344","summary":"Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).","details":"Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).","published":"2021-08-13T12:15:07.007","modified":"2026-06-17T04:00:22.987","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.96772,"percentile":0.99885,"asOf":"2026-09-13"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.nagios.com/downloads/nagios-xi/change-log/"},{"type":"ADVISORY","url":"https://www.nagios.com/downloads/nagios-xi/change-log/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T04:00:22.987"}}