PT-2025-44507 · Nagios Enterprises · Nagios Xi
Matthew Bach
·
Publicado
2025-10-30
·
Atualizado
2025-10-30
·
CVE-2024-14009
CVSS v4.0
9.4
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 2024R1.0.1
Description
Nagios XI versions prior to 2024R1.0.1 have a privilege escalation issue within the System Profile component. This component is an administrative diagnostic and configuration capability. Improper access controls and unsafe handling of exported/imported profile data and operations could allow an authenticated administrator to execute actions on the underlying XI host outside the application's security scope, potentially leading to root privileges on the XI server.
Recommendations
Update to version 2024R1.0.1 or later.
Correção
LPE
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nagios Xi