PT-2025-44491 · Nagios Enterprises · Nagios Xi

Published

2025-10-30

·

Updated

2025-11-06

·

CVE-2023-7317

CVSS v4.0
10
VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1
Description Nagios XI versions prior to 2024R1 have a missing access control issue through the Web SSH Terminal. A remote attacker with low privileges could access or interact with the terminal interface without proper authorization. This could lead to unauthorized command execution or the exposure of sensitive information.
Recommendations Update to version 2024R1 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-14492
CVE-2023-7317

Affected Products

Nagios Xi