home.social

#nagiosxi — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #nagiosxi, aggregated by home.social.

fetched live
  1. Nagios XI (pre-2024R2) hit by CRITICAL OS command injection (CVE-2025-34284, CVSS 9.4) in WinRM plugin. Auth'd admins can execute arbitrary OS commands. Upgrade ASAP & lock down admin access. radar.offseq.com/threat/cve-20 #OffSeq #NagiosXI #Vuln #Security

  2. Nagios XI (pre-2024R2) hit by CRITICAL OS command injection (CVE-2025-34284, CVSS 9.4) in WinRM plugin. Auth'd admins can execute arbitrary OS commands. Upgrade ASAP & lock down admin access. radar.offseq.com/threat/cve-20 #OffSeq #NagiosXI #Vuln #Security

  3. 🚨 CVE-2025-34134: CRITICAL RCE in Nagios XI BPI pre-2024R1.4.2. Admins can exploit weak config sanitization to execute arbitrary code via webroot file creation. Patch now, restrict admin access, and monitor logs! radar.offseq.com/threat/cve-20 #OffSeq #NagiosXI #Vuln #RCE

  4. 🚨 CVE-2025-34134: CRITICAL RCE in Nagios XI BPI pre-2024R1.4.2. Admins can exploit weak config sanitization to execute arbitrary code via webroot file creation. Patch now, restrict admin access, and monitor logs! radar.offseq.com/threat/cve-20 #OffSeq #NagiosXI #Vuln #RCE

  5. Nagios XI (pre-2026R1) faces a CRITICAL OS command injection (CVE-2025-34286) in Core Config Manager. Authenticated admins can run arbitrary commands—risking full host compromise. Restrict admin access & prep for patch! radar.offseq.com/threat/cve-20 #OffSeq #NagiosXI #Vuln #Cybersecurity

  6. Nagios XI (pre-2026R1) faces a CRITICAL OS command injection (CVE-2025-34286) in Core Config Manager. Authenticated admins can run arbitrary commands—risking full host compromise. Restrict admin access & prep for patch! radar.offseq.com/threat/cve-20 #OffSeq #NagiosXI #Vuln #Cybersecurity

  7. Анализ уязвимостей CVE-2024-24401 и CVE-2024-24402 в Nagios XI

    Предисловие Всем привет, меня зовут Дмитрий, я работаю специалистом по моделированию атак в компании «Перспективный мониторинг». Я занимаюсь разработкой сценариев атак для киберполигона Ampire. Когда мы с командой тестируем актуальные уязвимости, процесс выглядит так: устанавливаем уязвимую версию ПО, проверяем работоспособность Proof of Concept, после чего обновляемся до актуальной версии и убеждаемся, что уязвимость устранена. Тестируя актуальные уязвимости в системе мониторинга Nagios Xi, я обнаружил, что в сети очень мало информации об уязвимостях CVE-2024-24401 и CVE-2024-24402. К тому же оказалось, что одна из уязвимостей, а именно уязвимость локального повышения привилегий CVE-2024-24402, не была полностью пропатчена.

    habr.com/ru/companies/pm/artic

    #исследование_программ #информационная_безопасность #information_security #cve #nagiosxi #rce #lpe #уязвимости #sql_injection #взлом

  8. Анализ уязвимостей CVE-2024-24401 и CVE-2024-24402 в Nagios XI

    Предисловие Всем привет, меня зовут Дмитрий, я работаю специалистом по моделированию атак в компании «Перспективный мониторинг». Я занимаюсь разработкой сценариев атак для киберполигона Ampire. Когда мы с командой тестируем актуальные уязвимости, процесс выглядит так: устанавливаем уязвимую версию ПО, проверяем работоспособность Proof of Concept, после чего обновляемся до актуальной версии и убеждаемся, что уязвимость устранена. Тестируя актуальные уязвимости в системе мониторинга Nagios Xi, я обнаружил, что в сети очень мало информации об уязвимостях CVE-2024-24401 и CVE-2024-24402. К тому же оказалось, что одна из уязвимостей, а именно уязвимость локального повышения привилегий CVE-2024-24402, не была полностью пропатчена.

    habr.com/ru/companies/pm/artic

    #исследование_программ #информационная_безопасность #information_security #cve #nagiosxi #rce #lpe #уязвимости #sql_injection #взлом

  9. Two minutes into trying out #NagiosXI and I'm basically blocked from doing anything because the trial licence is 7 nodes, 50 services and auto discovery found more than that on my home network. Over $2.5k USD for 100 nodes, far too rich for my home setup - also seems to hint at license expiry - without any actual detail on how long that license is for. Auto-discovery was good though, liked that bit.

    Going to try Prometheus next.
  10. Two minutes into trying out #NagiosXI and I'm basically blocked from doing anything because the trial licence is 7 nodes, 50 services and auto discovery found more than that on my home network. Over $2.5k USD for 100 nodes, far too rich for my home setup - also seems to hint at license expiry - without any actual detail on how long that license is for. Auto-discovery was good though, liked that bit.

    Going to try Prometheus next.
  11. Two minutes into trying out #NagiosXI and I'm basically blocked from doing anything because the trial licence is 7 nodes, 50 services and auto discovery found more than that on my home network. Over $2.5k USD for 100 nodes, far too rich for my home setup - also seems to hint at license expiry - without any actual detail on how long that license is for. Auto-discovery was good though, liked that bit.

    Going to try Prometheus next.
  12. Two minutes into trying out #NagiosXI and I'm basically blocked from doing anything because the trial licence is 7 nodes, 50 services and auto discovery found more than that on my home network. Over $2.5k USD for 100 nodes, far too rich for my home setup - also seems to hint at license expiry - without any actual detail on how long that license is for. Auto-discovery was good though, liked that bit.

    Going to try Prometheus next.