PT-2025-44523 · Nagios Enterprises · Nagios Xi
D3Lt4
·
Publicado
2025-09-24
·
Atualizado
2025-10-31
·
CVE-2025-34286
CVSS v4.0
9.4
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 2026R1
Description
Nagios XI versions prior to 2026R1 contain a remote code execution issue in the Core Config Manager (CCM) Run Check command. Insufficient validation and escaping of parameters used to construct backend command lines allows an authenticated administrator to inject shell metacharacters that are executed on the server. Successful exploitation results in arbitrary command execution with the privileges of the Nagios XI web application user, potentially leading to control of the underlying host operating system.
Recommendations
Nagios XI versions prior to 2026R1 should be updated to version 2026R1 or later.
Correção
RCE
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nagios Xi