CVE-2025-34287

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could modify its contents, leading to arbitrary code execution as the nagios user when the script is next run. This improper ownership and permission configuration enables local privilege escalation.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-30 22:15

Updated : 2025-10-30 22:15


NVD link : CVE-2025-34287

Mitre link : CVE-2025-34287

CVE.ORG link : CVE-2025-34287


JSON object : View

Products Affected

No product.

CWE
CWE-732

Incorrect Permission Assignment for Critical Resource