CVE-2025-34134
- EPSS 0.9%
- Veröffentlicht 30.10.2025 21:41:58
- Zuletzt bearbeitet 06.11.2025 18:17:25
Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization of administrator-controlled BPI configuration parameters (notably bpi_...
- EPSS 0.02%
- Veröffentlicht 30.10.2025 21:41:36
- Zuletzt bearbeitet 06.11.2025 14:13:16
Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions and missing synchronization or final-path validation, a l...
CVE-2024-14009
- EPSS 0.2%
- Veröffentlicht 30.10.2025 21:41:13
- Zuletzt bearbeitet 06.11.2025 18:17:08
Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an administrative diagnostic/configuration capability. Due to improper access controls and unsafe handl...
CVE-2024-14004
- EPSS 0.1%
- Veröffentlicht 30.10.2025 21:40:51
- Zuletzt bearbeitet 06.11.2025 16:08:49
Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validated configurat...
CVE-2018-25123
- EPSS 0.03%
- Veröffentlicht 30.10.2025 21:40:26
- Zuletzt bearbeitet 05.11.2025 18:26:40
Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-related processes/scripts executed with excessive privileges, allowing a local attacker with limited system access to abuse file/comma...
CVE-2020-36868
- EPSS 0.05%
- Veröffentlicht 30.10.2025 21:40:03
- Zuletzt bearbeitet 05.11.2025 18:23:19
Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routines using insecure file/command handling and insufficient validation of ...
CVE-2025-34287
- EPSS 0.02%
- Veröffentlicht 30.10.2025 21:39:43
- Zuletzt bearbeitet 06.11.2025 18:12:41
Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges cou...
CVE-2025-34135
- EPSS 0.04%
- Veröffentlicht 30.10.2025 21:39:22
- Zuletzt bearbeitet 06.11.2025 18:16:51
Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. In particular, the nagios.service unit had executable permissions that were not required. Overly permissive permissions on service...
CVE-2021-47700
- EPSS 0.12%
- Veröffentlicht 30.10.2025 21:39:02
- Zuletzt bearbeitet 05.11.2025 18:22:22
Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking di...
CVE-2024-14006
- EPSS 0.18%
- Veröffentlicht 30.10.2025 21:38:42
- Zuletzt bearbeitet 06.11.2025 16:35:11
Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can sup...