Privilege Escalation Vulnerability in Nagios XI by Nagios
CVE-2011-10035

7.3HIGH

Key Information:

Vendor

NagiOS

Status
Vendor
CVE Published:
30 October 2025

What is CVE-2011-10035?

Nagios XI prior to version 2011R1.9 is susceptible to privilege escalation due to flaws in the scripts responsible for installing or updating system crontab entries. The problem arises from time-of-check/time-of-use race conditions that occur alongside inadequate synchronization and missing validation checks for final paths. A local user with low privileges can exploit these vulnerabilities by manipulating the filesystem state during crontab installation. This can lead to the execution of commands or files with higher privileges, potentially compromising the system's security integrity.

Affected Version(s)

XI 0 < 2011R1.9

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0a29406d9794e4f9b30b3c5d6702c708
.
CVE-2011-10035 : Privilege Escalation Vulnerability in Nagios XI by Nagios