← CVE Tracker
7.2HIGH

CVE-2024-13997 — Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an…

Nagios · Nagios Xi · Published 3 Nov 2025 · Modified 26 Sept 2026

Description

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.

References

What to do
  1. Check whether Nagios Xi is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2024-13997