
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-13997 is a privilege escalation vulnerability in Nagios XI that allows an authenticated administrator to leverage the Migrate Server feature to obtain root privileges on the underlying host operating system. It affects Nagios XI versions prior to 2024R1.1.3, including 2024R1, 2024R1.0.1, 2024R1.0.2, 2024R1.1, 2024R1.1.1, and 2024R1.1.2, as well as all versions before the 2024 release line. The vulnerability was published on November 3, 2025, and was assigned by VulnCheck. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 9.4 (Critical) (Nagios Security, VulnCheck Advisory).
The root cause is classified as CWE-269 (Improper Privilege Management), where the Migrate Server feature in Nagios XI fails to enforce appropriate privilege boundaries during its migration workflow. An authenticated administrator-level user can abuse this workflow to execute actions outside the intended security scope of the application, ultimately achieving root-level access on the underlying XI host operating system. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require high privileges (admin credentials) as a precondition. No public proof-of-concept exploit code has been identified at this time (Nagios Security, VulnCheck Advisory).
Successful exploitation grants an admin-level attacker full root control of the Nagios XI host operating system, enabling complete system compromise beyond the application's intended security boundary. This includes unauthorized access to all data on the host, the ability to install persistent backdoors or malware, and potential for lateral movement to other systems monitored or accessible from the Nagios XI server. Given that Nagios XI typically has broad network visibility and credentials for monitored infrastructure, a compromised host could expose an organization's entire monitoring environment and the systems it manages (VulnCheck Advisory, ENISA EUVD).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.134%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated administrator-level access, which limits the attack surface compared to unauthenticated vulnerabilities (VulnCheck Advisory, Feedly).
Nagios has released version 2024R1.1.3 which addresses this privilege escalation vulnerability. Organizations should upgrade to Nagios XI 2024R1.1.3 or later as the primary remediation step. As additional hardening measures, administrators should implement multi-factor authentication for admin accounts, enforce strict access controls limiting administrative privileges to only necessary personnel, and audit administrative actions — particularly any use of the Migrate Server feature — for anomalous activity (Nagios Security, Nagios Changelog).
The vulnerability was noted across several vulnerability tracking platforms and security feeds shortly after publication, including CIRCL Vulnerability Lookup, ENISA EUVD, and VulnDB. Social media activity was limited to automated CVE tracking accounts on Bluesky. No significant researcher commentary or vendor statements beyond the patch release have been identified (ENISA EUVD, CIRCL Lookup).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."