Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5359-gfvc-c3p7

Опубликовано: 04 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 7.2

Описание

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.

EPSS

Процентиль: 36%
0.00153
Низкий

9.4 Critical

CVSS4

7.2 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.2
nvd
3 месяца назад

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.

CVSS3: 9.1
fstec
больше 1 года назад

Уязвимость инструмента для мониторинга ИТ-инфраструктуры Nagios XI, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 36%
0.00153
Низкий

9.4 Critical

CVSS4

7.2 High

CVSS3

Дефекты

CWE-269