Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient authorization, potentially allowing unauthorized command execution or disclosure of sensitive information.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "It was discovered that the Web SSH Terminal in Nagios XI was missing access controls" and "Fixed some missing access controls in the Nagios XI 5 API."


Workaround

Disable the web SSH terminal.

History

Fri, 31 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios xi
Vendors & Products Nagios
Nagios xi

Thu, 30 Oct 2025 22:00:00 +0000

Type Values Removed Values Added
Description Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient authorization, potentially allowing unauthorized command execution or disclosure of sensitive information.
Title Nagios XI < 2024R1 Web SSH Terminal Missing Access Control
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-31T13:23:05.947Z

Reserved: 2025-10-21T22:06:36.604Z

Link: CVE-2023-7317

cve-icon Vulnrichment

Updated: 2025-10-31T13:05:33.134Z

cve-icon NVD

Status : Received

Published: 2025-10-30T22:15:43.630

Modified: 2025-10-30T22:15:43.630

Link: CVE-2023-7317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-31T10:13:17Z