CVE-2024-13986: Nagios XI < 2024R1.3.2 Authenticated Arbitrary File Upload Path Traversal RCE
Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface. The issue arises from insufficient validation of file paths and extensions during MIB upload and snapshot rename operations. Exploitation results in the placement of attacker-controlled PHP files in a web-accessible directory, executed as the www-data user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13986?
CVE-2024-13986 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-13986?
To mitigate CVE-2024-13986, it is recommended to update Nagios XI to version 2024R1.3.2 or later.
What type of vulnerability is CVE-2024-13986?
CVE-2024-13986 is a remote code execution vulnerability resulting from an arbitrary file upload and path traversal issues.
Which versions of Nagios XI are affected by CVE-2024-13986?
CVE-2024-13986 affects versions of Nagios XI prior to 2024R1.3.2.
What causes the vulnerability CVE-2024-13986?
CVE-2024-13986 is caused by insufficient validation of file paths and extensions during MIB uploads and snapshot handling.