GPU VulnDB

Database/Control plane, storage & DevOps

Nagios XI: systemd unit files shipped with unnecessary executable permissions

CVSS 5.1CVE-2025-34135Control plane, storage & DevOpscurated

Impact

Nagios XI before 2024R1.4.2 installs systemd unit files, notably nagios.service, with permission bits broader than needed - the unit is marked executable. On its own this grants nothing; it widens local attack surface by allowing unintended execution behaviour and makes abuse of service operations easier when chained with another local weakness on the monitoring host. That host matters more than its CVSS suggests: a datacenter Nagios XI box typically holds SSH keys, SNMP and IPMI credentials for the fleet it polls, so anything that eases local escalation there is worth closing.

Who can reach it

A local user with a shell on the Nagios XI server. No remote path, and no impact by itself - it is a hardening defect that helps an attacker who already has local access.

What to do

Upgrade Nagios XI to 2024R1.4.2 or later, which corrects the shipped permissions; the upgrade restarts the monitoring daemons and briefly interrupts polling. If an upgrade is not scheduled, the bits can be corrected in place (remove the executable bit from the unit files under the Nagios unit directory) followed by systemctl daemon-reload. No reboot.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.