PT-2025-44507 · Nagios Enterprises · Nagios Xi

Matthew Bach

·

Publicado

2025-10-30

·

Atualizado

2025-10-30

·

CVE-2024-14009

CVSS v4.0

9.4

Crítica

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.0.1
Description Nagios XI versions prior to 2024R1.0.1 have a privilege escalation issue within the System Profile component. This component is an administrative diagnostic and configuration capability. Improper access controls and unsafe handling of exported/imported profile data and operations could allow an authenticated administrator to execute actions on the underlying XI host outside the application's security scope, potentially leading to root privileges on the XI server.
Recommendations Update to version 2024R1.0.1 or later.

Correção

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-14534
CVE-2024-14009

Produtos afetados

Nagios Xi