CVE-2024-24402: Critical severity Nagios XI vulnerability
Published Feb 26, 2024
·Updated
An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.
Affected Software
2 affected components
Nagios XI
Nagios Nagios XI=2024-r1.0.1
Event History
Feb 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24402?
CVE-2024-24402 has been classified as a high-severity vulnerability due to its potential for remote privilege escalation.
2
How do I fix CVE-2024-24402?
To fix CVE-2024-24402, update Nagios XI to the latest version as specified in the official patch notes from Nagios.
3
Who is affected by CVE-2024-24402?
CVE-2024-24402 affects users of Nagios XI version 2024R1.01 who have not applied the necessary security updates.
4
What type of vulnerability is CVE-2024-24402?
CVE-2024-24402 is a remote privilege escalation vulnerability that allows attackers to execute unauthorized scripts.
5
Can CVE-2024-24402 be exploited remotely?
Yes, CVE-2024-24402 can be exploited remotely by an attacker who crafts a specific payload targeting the NPCD component.