Nagios XI Under Attack: SQL Injection Vulnerability Allows Remote Code Execution
CVE-2024-24401

Currently unrated

Key Information:

Vendor

Nagios

Status
Vendor
CVE Published:
26 February 2024

What is CVE-2024-24401?

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

References

EPSS Score

57% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-24401 : Nagios XI Under Attack: SQL Injection Vulnerability Allows Remote Code Execution