Aller au contenu

Fiche vulnérabilité

CVE-2025-34227 : faille élevée nagios nagios xi (CVSS 8.8)

Description

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
25 sept. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • nagios nagios xi

Références

Rechercher une autre vulnérabilité dans la base CVE