PT-2025-44507 · Nagios Enterprises · Nagios Xi

Matthew Bach

·

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2024-14009

CVSS v4.0
9.4
VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.0.1
Description Nagios XI versions prior to 2024R1.0.1 have a privilege escalation issue within the System Profile component. This component is an administrative diagnostic and configuration capability. Improper access controls and unsafe handling of exported/imported profile data and operations could allow an authenticated administrator to execute actions on the underlying XI host outside the application's security scope, potentially leading to root privileges on the XI server.
Recommendations Update to version 2024R1.0.1 or later.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-14534
CVE-2024-14009

Affected Products

Nagios Xi