CVE 9.4 CRITICAL

Nagios XI < 2024R2 Authenticated Command Injection via WinRM Plugin_CVE-2025-34284

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command invocations. Successful exploitation enables arbitrary command execution with the privileges of the Nagios XI web application user and can be leveraged to modify configuration, exfiltrate data, disrupt monitoring operations, or execute commands on the underlying host operating system.

AI Analysis

Command injection vulnerability in the WinRM plugin of Nagios XI, allowing arbitrary command execution with the privileges of the Nagios XI web application user.

Basic Information

ID CVE-2025-34284
Source VulnCheck
Published Oct 30, 2025 at 21:30

Affected Product

Vendor Nagios
Product XI

CWE Classification

AI Assessment

AI Score 9.4 / 10
AI Severity Critical
Vendor Nagios
Product Nagios XI
Version < 2024R2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.