Aller au contenu

Fiche vulnérabilité

CVE-2024-13986 : faille élevée nagios nagios xi (CVSS 8.8)

Description

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface. The issue arises from insufficient validation of file paths and extensions during MIB upload and snapshot rename operations. Exploitation results in the placement of attacker-controlled PHP files in a web-accessible directory, executed as the www-data user.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
28 août 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • nagios nagios xi

Références

Rechercher une autre vulnérabilité dans la base CVE