nagios security advisories
13 threat alerts tracking vulnerabilities and security advisories that affect nagios products.
Vulnios monitors nagios CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent nagios security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2021-3193 — nagios — nagios_xi
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
criticalCVE-2021-3193Critical Vulnerability: CVE-2020-15903 — nagios — nagios_xi
An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was f
criticalCVE-2020-15903Critical Vulnerability: CVE-2018-17148 — nagios — nagios_xi
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain ac
criticalCVE-2018-17148Critical Vulnerability: CVE-2019-12279 — nagios — nagios_xi
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the is
criticalCVE-2019-12279Critical Vulnerability: CVE-2019-9165 — nagios — nagios_xi
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.
criticalCVE-2019-9165Critical Vulnerability: CVE-2019-9204 — nagios — incident_manager
SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.
criticalCVE-2019-9204Critical Vulnerability: CVE-2019-9203 — nagios — incident_manager
Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.
criticalCVE-2019-9203Critical Vulnerability: CVE-2018-15708 — nagios — nagios_xi
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
criticalCVE-2018-15708Critical Vulnerability: CVE-2018-8734 — nagios — nagios_xi
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.
criticalCVE-2018-8734Critical Vulnerability: CVE-2018-8733 — nagios — nagios_xi
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authentic
criticalCVE-2018-8733Critical Vulnerability: CVE-2016-0726 — nagios — nagios
The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of
criticalCVE-2016-0726Critical Vulnerability: CVE-2016-9565 — nagios — nagios
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed serve
criticalCVE-2016-9565Critical Vulnerability: CVE-2012-10063 — nagios — nagios_xi
Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQL queries by supplying craft
criticalCVE-2012-10063
Track nagios exposure across your environment
Vulnios automatically cross-references your asset inventory against new nagios CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan