NA

CVE-2024-33775

Published: 01/05/2024 Updated: 02/05/2024

Vulnerability Summary

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote malicious user to escalate privileges via a crafted Dashlet.

Github Repositories

CVE Discovered by: K Wahab (Neo`X) Vulnerability Details: Product: Nagios XI Version 2024R101 Vulnerability: Privilege Escalation from Users "NAGIOS" or "APACHE" Result: Full root access on the target system CVE: cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2024-33775 Exploit: RSS Dashlet is used in this example 1 Create a new instance of Nagios