PT-2025-44507 · Nagios Enterprises · Nagios Xi
Matthew Bach
·
Published
2025-10-30
·
Updated
2025-10-30
·
CVE-2024-14009
CVSS v4.0
9.4
Critical
| AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 2024R1.0.1
Description
Nagios XI versions prior to 2024R1.0.1 have a privilege escalation issue within the System Profile component. This component is an administrative diagnostic and configuration capability. Improper access controls and unsafe handling of exported/imported profile data and operations could allow an authenticated administrator to execute actions on the underlying XI host outside the application's security scope, potentially leading to root privileges on the XI server.
Recommendations
Update to version 2024R1.0.1 or later.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Xi