Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-34287

Опубликовано: 30 окт. 2025
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could modify its contents, leading to arbitrary code execution as the nagios user when the script is next run. This improper ownership and permission configuration enables local privilege escalation.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Версия до 2024 (исключая)
cpe:2.3:a:nagios:nagios_xi:2024:r1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.0.1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.0.2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.1.2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.1.3:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.1.4:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.1.5:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.2.1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.2.2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.3:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.3.1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.3.2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.3.3:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.3.4:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.4:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.4.1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.4.2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.4.3:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.4.4:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.0027
Низкий

7.8 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
github
10 месяцев назад

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could modify its contents, leading to arbitrary code execution as the nagios user when the script is next run. This improper ownership and permission configuration enables local privilege escalation.

CVSS3: 7.3
fstec
10 месяцев назад

Уязвимость сценария process_perfdata.pl инструмента для мониторинга ИТ-инфраструктуры Nagios XI, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 19%
0.0027
Низкий

7.8 High

CVSS3

Дефекты

CWE-732