Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-14006


Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to poison generated links or responses, which may facilitate phishing of credentials, account recovery link hijacking, and web cache poisoning.


Published

2025-10-30T22:15:46.153

Last Modified

2025-11-06T16:35:11.600

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-346

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nagios nagios_xi < 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes
Application nagios nagios_xi 2024 Yes

References