CVE-2024-54957

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 27, 2025
Updated: Mar 3, 2025
CWE ID 601

Summary

CVE-2024-54957 is a newly disclosed vulnerability affecting Nagios XI 2024R1.2.2. This issue permits users with read-only access to redirect victims to malicious external URLs via an open redirect flaw on the Tools page. The vulnerability does not require administrative privileges, making it a potential threat to organizations that have implemented access controls but failed to account for this specific risk. The attacker can manipulate users into clicking on the malicious link, potentially exposing them to phishing attacks, malware, or other security threats. Organizations using Nagios XI 2024R1.2.2 should apply the necessary patches or mitigations as soon as possible to protect their networks and users from potential exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Nagios Core

Affected Vendors

  • Nagios Enterprises LLC