QID 379425

Date Published: 2024-02-28

QID 379425: Nagios XI Multiple Vulnerabilities

Nagios XI is a comprehensive monitoring and alerting solution designed to help organizations track the health and performance of their IT infrastructure, including servers, networks, applications, and services, through centralized management and customizable notifications.

Nagios XI is vulnerable to the following vulnerabilities:

  • CVE-2024-24401: SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
  • CVE-2024-24402: An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of Nagios XI by extracting the version from the '/usr/local/nagiosxi/var/xiversion' file.

Successful exploitation of the vulnerability may allow a low privileged user to execute arbitrary code and escalate privileges, leading to complete system compromise.

  • CVSS V3 rated as Critical - 9.9 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to upgrade to Nagios XI version 2024R1.0.2 or later. For more information, please refer to the Nagios XI Release Notes .

    Vendor References

    CVEs related to QID 379425

    Software Advisories
    Advisory ID Software Component Link
    Nagios Security Advisory URL Logo www.nagios.com/changelog/