PT-2025-44511 · Nagios Enterprises · Nagios Xi

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2025-34135

CVSS v4.0
5.1
VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.4.2
Description Nagios XI versions prior to 2024R1.4.2 configure certain systemd unit files with overly permissive permissions. Specifically, the
nagios.service
unit possesses unnecessary executable permissions. These permissions can expand the local attack surface, potentially enabling unintended execution or facilitating abuse of service operations when combined with other weaknesses.
Recommendations Update Nagios XI to version 2024R1.4.2 or later.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2025-14491
CVE-2025-34135

Affected Products

Nagios Xi