Advisories

Nagios XI < 2024R1 Web SSH Terminal Missing Access Control

Go Back
severity
critical
date
Affecting
  • XI < 2024R1

CWE
  • CWE-862 Missing Authorization
CVSS
9.4
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Credit
Pankaj Kumar Thrakur
Description
Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient authorization, potentially allowing unauthorized command execution or disclosure of sensitive information.