Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive information from the underlying host.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 31 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Nagios
         Nagios xi  | 
|
| Vendors & Products | 
        
        Nagios
         Nagios xi  | 
Thu, 30 Oct 2025 21:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive information from the underlying host. | |
| Title | Nagios XI < 2024R1.1.4 Authenticated Local File Inclusion via NagVis | |
| Weaknesses | CWE-98 | |
| References | 
         | |
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-10-30T21:30:39.691Z
Updated: 2025-10-31T15:05:11.624Z
Reserved: 2025-10-22T18:20:05.591Z
Link: CVE-2024-14002
Updated: 2025-10-31T15:05:07.731Z
Status : Received
Published: 2025-10-30T22:15:45.600
Modified: 2025-10-30T22:15:45.600
Link: CVE-2024-14002
No data.