CVE-2024-14004

HIGH WAF: Low
CVSS 8.8 Published: 2025-10-30
CWE-269

Nagios XI versions prior to 2024R1.2 containĀ a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validated configuration settings to obtain elevated privileges on the Nagios XI system.

WAF Coverage Analysis

Improper Privilege Management Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
nagiosnagios_xiup to 2024
nagiosnagios_xi2024
nagiosnagios_xi2024
nagiosnagios_xi2024
nagiosnagios_xi2024
nagiosnagios_xi2024
nagiosnagios_xi2024
nagiosnagios_xi2024
nagiosnagios_xi2024
nagiosnagios_xi2024

References

Back to CVE Database