Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-related processes/scripts executed with excessive privileges, allowing a local attacker with limited system access to abuse file/command execution paths or writable resources to gain elevated privileges.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "Fixed privilege escalation security vulnerability in MRTG graphing component by running as nagios user/group."


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Nagios nagios Xi
CPEs cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Vendors & Products Nagios nagios Xi
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 31 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios nagios
Nagios xi
Vendors & Products Nagios
Nagios nagios
Nagios xi

Thu, 30 Oct 2025 21:45:00 +0000

Type Values Removed Values Added
Description Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-related processes/scripts executed with excessive privileges, allowing a local attacker with limited system access to abuse file/command execution paths or writable resources to gain elevated privileges.
Title Nagios XI < 5.5.7 Privilege Escalation via MRTG Graphing Component
Weaknesses CWE-250
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-17T18:21:39.196Z

Reserved: 2025-10-29T20:49:14.561Z

Link: CVE-2018-25123

cve-icon Vulnrichment

Updated: 2025-10-31T13:05:59.502Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-30T22:15:37.967

Modified: 2025-11-05T18:26:40.703

Link: CVE-2018-25123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-31T10:13:24Z

Weaknesses