← Back

CVE-2024-13986

nvd nist
Published: Aug 28, 2025Modified: Nov 4, 2025

JSON object

Loading...
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)

Description

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface. The issue arises from insufficient validation of file paths and extensions during MIB upload and snapshot rename operations. Exploitation results in the placement of attacker-controlled PHP files in a web-accessible directory, executed as the www-data user.

Affected (14)

Products: Nagios: Nagios Xi
1 product
Nagios Xi
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Nagios
Before 2024
Version 2024 r1.0.1
Version 2024 r1.1.1
Version 2024 r1.1.2
Version 2024 r1.1.3
Version 2024 r1.1.4
Version 2024 r1.1.5
Version 2024 r1.1
Version 2024 r1.2.1
Version 2024 r1.2.2
Version 2024 r1.2
Version 2024 r1.3.1
Version 2024 r1.3
Version 2024 r1

References (5)

Source: disclosure@vulncheck.com
ExploitThird Party Advisory
Source: disclosure@vulncheck.com
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.