PT-2025-44502 · Nagios Enterprises · Nagios Xi

Exodus Intelligence

·

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2024-14003

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.2
Description The software contains a flaw due to insufficient validation of inbound NRDP (Nagios Remote Data Processor) request parameters. This allows crafted input to reach command execution paths, potentially enabling an attacker to execute arbitrary commands on the underlying host in the context of the web/Nagios service. The issue affects the NRDP server plugins.
Recommendations Update to version 2024R1.2 or later.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14305
CVE-2024-14003

Affected Products

Nagios Xi