CVE-2024-13997
Severity CVSS v4.0:
CRITICAL
Type:
CWE-269
Improper Privilege Management
Publication date:
03/11/2025
Last modified:
06/11/2025
Description
Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* | 2024 (excluding) | |
| cpe:2.3:a:nagios:nagios_xi:2024:r1:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2024:r1.0.1:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2024:r1.0.2:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2024:r1.1:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2024:r1.1.1:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2024:r1.1.2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



