Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-10035


Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions and missing synchronization or final-path validation, a local low-privileged user could manipulate filesystem state during crontab installation to influence the files or commands executed with elevated privileges, resulting in execution with higher privileges.


Published

2025-10-30T22:15:34.733

Last Modified

2025-11-06T14:13:16.653

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nagios nagios_xi ≤ 2009 Yes
Application nagios nagios_xi 2011 Yes
Application nagios nagios_xi 2011 Yes
Application nagios nagios_xi 2011 Yes
Application nagios nagios_xi 2011 Yes
Application nagios nagios_xi 2011 Yes
Application nagios nagios_xi 2011 Yes
Application nagios nagios_xi 2011 Yes
Application nagios nagios_xi 2011 Yes
Application nagios nagios_xi 2011 Yes

References