#nagiosxi — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #nagiosxi, aggregated by home.social.
-
Nagios XI (pre-2024R2) hit by CRITICAL OS command injection (CVE-2025-34284, CVSS 9.4) in WinRM plugin. Auth'd admins can execute arbitrary OS commands. Upgrade ASAP & lock down admin access. https://radar.offseq.com/threat/cve-2025-34284-cwe-78-improper-neutralization-of-s-1addf98c #OffSeq #NagiosXI #Vuln #Security
-
Nagios XI (pre-2024R2) hit by CRITICAL OS command injection (CVE-2025-34284, CVSS 9.4) in WinRM plugin. Auth'd admins can execute arbitrary OS commands. Upgrade ASAP & lock down admin access. https://radar.offseq.com/threat/cve-2025-34284-cwe-78-improper-neutralization-of-s-1addf98c #OffSeq #NagiosXI #Vuln #Security
-
🚨 CVE-2025-34134: CRITICAL RCE in Nagios XI BPI pre-2024R1.4.2. Admins can exploit weak config sanitization to execute arbitrary code via webroot file creation. Patch now, restrict admin access, and monitor logs! https://radar.offseq.com/threat/cve-2025-34134-cwe-78-improper-neutralization-of-s-ab21e3af #OffSeq #NagiosXI #Vuln #RCE
-
🚨 CVE-2025-34134: CRITICAL RCE in Nagios XI BPI pre-2024R1.4.2. Admins can exploit weak config sanitization to execute arbitrary code via webroot file creation. Patch now, restrict admin access, and monitor logs! https://radar.offseq.com/threat/cve-2025-34134-cwe-78-improper-neutralization-of-s-ab21e3af #OffSeq #NagiosXI #Vuln #RCE
-
Nagios XI (pre-2026R1) faces a CRITICAL OS command injection (CVE-2025-34286) in Core Config Manager. Authenticated admins can run arbitrary commands—risking full host compromise. Restrict admin access & prep for patch! https://radar.offseq.com/threat/cve-2025-34286-cwe-78-improper-neutralization-of-s-efb80336 #OffSeq #NagiosXI #Vuln #Cybersecurity
-
Nagios XI (pre-2026R1) faces a CRITICAL OS command injection (CVE-2025-34286) in Core Config Manager. Authenticated admins can run arbitrary commands—risking full host compromise. Restrict admin access & prep for patch! https://radar.offseq.com/threat/cve-2025-34286-cwe-78-improper-neutralization-of-s-efb80336 #OffSeq #NagiosXI #Vuln #Cybersecurity
-
Анализ уязвимостей CVE-2024-24401 и CVE-2024-24402 в Nagios XI
Предисловие Всем привет, меня зовут Дмитрий, я работаю специалистом по моделированию атак в компании «Перспективный мониторинг». Я занимаюсь разработкой сценариев атак для киберполигона Ampire. Когда мы с командой тестируем актуальные уязвимости, процесс выглядит так: устанавливаем уязвимую версию ПО, проверяем работоспособность Proof of Concept, после чего обновляемся до актуальной версии и убеждаемся, что уязвимость устранена. Тестируя актуальные уязвимости в системе мониторинга Nagios Xi, я обнаружил, что в сети очень мало информации об уязвимостях CVE-2024-24401 и CVE-2024-24402. К тому же оказалось, что одна из уязвимостей, а именно уязвимость локального повышения привилегий CVE-2024-24402, не была полностью пропатчена.
https://habr.com/ru/companies/pm/articles/861122/
#исследование_программ #информационная_безопасность #information_security #cve #nagiosxi #rce #lpe #уязвимости #sql_injection #взлом
-
Анализ уязвимостей CVE-2024-24401 и CVE-2024-24402 в Nagios XI
Предисловие Всем привет, меня зовут Дмитрий, я работаю специалистом по моделированию атак в компании «Перспективный мониторинг». Я занимаюсь разработкой сценариев атак для киберполигона Ampire. Когда мы с командой тестируем актуальные уязвимости, процесс выглядит так: устанавливаем уязвимую версию ПО, проверяем работоспособность Proof of Concept, после чего обновляемся до актуальной версии и убеждаемся, что уязвимость устранена. Тестируя актуальные уязвимости в системе мониторинга Nagios Xi, я обнаружил, что в сети очень мало информации об уязвимостях CVE-2024-24401 и CVE-2024-24402. К тому же оказалось, что одна из уязвимостей, а именно уязвимость локального повышения привилегий CVE-2024-24402, не была полностью пропатчена.
https://habr.com/ru/companies/pm/articles/861122/
#исследование_программ #информационная_безопасность #information_security #cve #nagiosxi #rce #lpe #уязвимости #sql_injection #взлом
-
Two minutes into trying out #NagiosXI and I'm basically blocked from doing anything because the trial licence is 7 nodes, 50 services and auto discovery found more than that on my home network. Over $2.5k USD for 100 nodes, far too rich for my home setup - also seems to hint at license expiry - without any actual detail on how long that license is for. Auto-discovery was good though, liked that bit.
Going to try Prometheus next. -
Two minutes into trying out #NagiosXI and I'm basically blocked from doing anything because the trial licence is 7 nodes, 50 services and auto discovery found more than that on my home network. Over $2.5k USD for 100 nodes, far too rich for my home setup - also seems to hint at license expiry - without any actual detail on how long that license is for. Auto-discovery was good though, liked that bit.
Going to try Prometheus next. -
Two minutes into trying out #NagiosXI and I'm basically blocked from doing anything because the trial licence is 7 nodes, 50 services and auto discovery found more than that on my home network. Over $2.5k USD for 100 nodes, far too rich for my home setup - also seems to hint at license expiry - without any actual detail on how long that license is for. Auto-discovery was good though, liked that bit.
Going to try Prometheus next. -
Two minutes into trying out #NagiosXI and I'm basically blocked from doing anything because the trial licence is 7 nodes, 50 services and auto discovery found more than that on my home network. Over $2.5k USD for 100 nodes, far too rich for my home setup - also seems to hint at license expiry - without any actual detail on how long that license is for. Auto-discovery was good though, liked that bit.
Going to try Prometheus next. -
The 8 Best Network Monitoring Tools for 2024 – Source: www.techrepublic.com https://ciso2ciso.com/the-8-best-network-monitoring-tools-for-2024-source-www-techrepublic-com/ #paesslerprtgnetworkmonitor #rssfeedpostgeneratorecho #SecurityonTechRepublic #ManageEngineOpManager #SecurityTechRepublic #ProgressWhatsUpGold #CyberSecurityNews #networkmonitoring #CloudSecurity #TopProducts #wireshark #NagiosXI #Security #Datadog #zabbix #Cacti
-
The 8 Best Network Monitoring Tools for 2024 – Source: www.techrepublic.com https://ciso2ciso.com/the-8-best-network-monitoring-tools-for-2024-source-www-techrepublic-com/ #paesslerprtgnetworkmonitor #rssfeedpostgeneratorecho #SecurityonTechRepublic #ManageEngineOpManager #SecurityTechRepublic #ProgressWhatsUpGold #CyberSecurityNews #networkmonitoring #CloudSecurity #TopProducts #wireshark #NagiosXI #Security #Datadog #zabbix #Cacti
-
The 8 Best Network Monitoring Tools for 2024 – Source: www.techrepublic.com https://ciso2ciso.com/the-8-best-network-monitoring-tools-for-2024-source-www-techrepublic-com/ #paesslerprtgnetworkmonitor #rssfeedpostgeneratorecho #SecurityonTechRepublic #ManageEngineOpManager #SecurityTechRepublic #ProgressWhatsUpGold #CyberSecurityNews #networkmonitoring #CloudSecurity #TopProducts #wireshark #NagiosXI #Security #Datadog #zabbix #Cacti
-
SecurityAffairs: Experts found critical flaws in Nagios XI network monitoring software https://securityaffairs.com/151138/security/nagios-xi-flaws.html #informationsecuritynews #ITInformationSecurity #PierluigiPaganini #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #Security #NagiosXI
-
SecurityOnline: Nagios XI Vulnerabilities: A Serious Risk to Organizations https://securityonline.info/nagios-xi-vulnerabilities-a-serious-risk-to-organizations/ #CVE-2023-40931 #CVE-2023-40932 #CVE-2023-40933 #CVE-2023-40934 #Vulnerability #NagiosXI