Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-14004


Nagios XI versions prior to 2024R1.2 containĀ a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validated configuration settings to obtain elevated privileges on the Nagios XI system.


Published

2025-10-30T22:15:45.877

Last Modified

2025-11-06T16:08:49.227

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nagios nagios_xi < 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes

References