Nagios XI < 2024R1.1.4 Authenticated Local File Inclusion via NagVis
Summary
| CVE | CVE-2024-14002 |
|---|---|
| State | PUBLISHED |
| Assigner | VulnCheck |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-30 22:15:45 UTC |
| Updated | 2026-10-02 00:10:00 UTC |
| Description | Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive information from the underlying host. |
Risk And Classification
Primary CVSS: v4.0 7.1 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.012860000 probability, percentile 0.691600000 (date 2026-10-05)
Problem Types: CWE-98 | CWE-98 CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 7.1 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 7.1 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Primary | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nagios | Nagios Xi | All | All | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.0.1 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.0.2 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.1 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.1.1 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.1.2 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.1.3 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.nagios.com/changelog/nagios-xi | [email protected] | www.nagios.com | Release Notes |
| www.vulncheck.com/advisories/nagios-xi-authenticated-local-file-inclusion-via-n... | [email protected] | www.vulncheck.com | Third Party Advisory |
| www.nagios.com/products/security | [email protected] | www.nagios.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Márk Rákóczi (en)
Additional Advisory Data
Solutions
CNA: Nagios addresses this vulnerability as "Nagios XI is vulnerable to an authenticated Local File Inclusion attack via Nagvis." and as part of "Fixed both XSS in Executive Summary report and ajaxhelper endpoint that was too open."