CVE-2024-13997
CRITICAL EPSS 58.7%
Published Nov 3, 20257mo ago · Modified Jun 17, 20261w ago
9.4 CVSS 4.0
Published Nov 3, 2025 7mo ago
Last Modified Jun 17, 2026 1w ago
Description
Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Attack Vector Network
Attack Complexity Low
Privileges Required High
User Interaction None
Scope X
Threat Intelligence
EPSS Exploit Probability
58.7% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-269 Improper Privilege Management Authorization
Affected Products 7
References 3
- nagios.com https://www.nagios.com/changelog/nagios-xi/
- nagios.com https://www.nagios.com/products/security/#nagios-xi
- vulncheck.com https://www.vulncheck.com/advisories/nagios-xi-privilege-escalation-via-migrate-server-feature-to-root-on-host
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.