← Global Threat Landscape

CVE-2019-15949

CWE-78

Critical

97.6

RPS

Description

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root.

Source: NVD

Signals

CVSS
8.8
High · v3.1
EPSS
77.03%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Nov 2021
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-78
Published
5 Sept 2019
Last modified 6 Nov 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2019-15949

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2019-15949 · RPS 97.6 · DevSecure Intelligence