Get real-time updates on Telegram
CVE-2025-34287: nagios xi before 2024 (exclusive), 2024 · update r1, 2024 · update r1.0.1 (+20 more affected versions); +1 more…
CVE-2025-34287. CVSS 3.1 base score 7.8 (HIGH, NVD). EPSS 0.00289 (percentile 0.19614), scored 2026-10-06.
Affected technology
nagios xi · before 2024 (exclusive)
nagios
nagios xi · 2024 · update r1
nagios
nagios xi · 2024 · update r1.0.1
nagios
nagios xi · 2024 · update r1.0.2
nagios
nagios xi · 2024 · update r1.1
nagios
nagios xi · 2024 · update r1.1.1
nagios
nagios xi · 2024 · update r1.1.2
nagios
nagios xi · 2024 · update r1.1.3
nagios
nagios xi · 2024 · update r1.1.4
nagios
nagios xi · 2024 · update r1.1.5
nagios
nagios xi · 2024 · update r1.2
nagios
nagios xi · 2024 · update r1.2.1
nagios
nagios xi · 2024 · update r1.2.2
nagios
nagios xi · 2024 · update r1.3
nagios
nagios xi · 2024 · update r1.3.1
nagios
nagios xi · 2024 · update r1.3.2
nagios
nagios xi · 2024 · update r1.3.3
nagios
nagios xi · 2024 · update r1.3.4
nagios
nagios xi · 2024 · update r1.4
nagios
nagios xi · 2024 · update r1.4.1
nagios
nagios xi · 2024 · update r1.4.2
nagios
nagios xi · 2024 · update r1.4.3
nagios
nagios xi · 2024 · update r1.4.4
nagios
XI · 0 to before 2024R2
Nagios
Description’s affected range: versions prior to 2024R2
Component: process_perfdata.pl
Attack conditions (Vendor/CNA, CVSS 4.0): Local · Low privileges required · No user interaction required
What an attacker can do
An attacker with web server privileges could modify its contents, leading to arbitrary code execution as the nagios user when the script is next run. Vendor/CNA’s CVSS 4.0 assessment (base score 8.4/10) rates confidentiality and integrity impact as high; availability impact as low.
- CWE
- CWE-732
- CCR priority
- 31.3 /100 (P4)
- CVSS 3.1
- 7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.00289 · percentile 0.19614 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-34287.html