PT-2025-44526 · Nagios Enterprises · Nagios Xi
Published
2025-10-30
·
Updated
2025-11-06
·
CVE-2011-10035
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 2011R1.9
Description
The software contains privilege escalation issues within scripts used for installing or updating system crontab entries. A local user with limited privileges could exploit time-of-check/time-of-use race conditions and a lack of proper synchronization or path validation to manipulate the filesystem during crontab installation. This manipulation could lead to the execution of commands with elevated privileges.
Recommendations
Update to version 2011R1.9 or later.
Fix
LPE
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Xi