
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet. The vulnerability was discovered by K. Wahab (Neo`X) and affects Nagios XI Version 2024R1.01. This security flaw enables privilege escalation from users 'NAGIOS' or 'APACHE' to gain full root access on the target system (GitHub POC).
The vulnerability exists in the Autodiscover component and can be exploited through the RSS Dashlet functionality. The issue has been assigned a CVSS v3.1 base score of 9.8 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and is classified under CWE-269 (Improper Privilege Management) (NVD Database).
The successful exploitation of this vulnerability allows attackers to escalate privileges from either NAGIOS or APACHE user to obtain full root access on the affected system. This represents a critical security risk as it provides attackers with complete control over the Nagios XI installation (GitHub POC).
The vulnerability can be exploited through two methods: as NAGIOS user by adding malicious content to dashlet .inc.php files in the '/usr/local/nagiosxi/html/includes/dashlets/' directory, or as APACHE user by uploading a modified malicious dashlet through the dashlets management page. Both methods ultimately lead to privilege escalation to root via the autodiscover_new.php script (GitHub POC).
The vulnerability has been addressed in newer versions of Nagios XI. Users should upgrade to version 2024R1.02 or later as indicated in the changelog (Nagios Changelog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."