关键漏洞信息 标题: Nagios XI < 2024R1.2 RCE via NRDP Server Plugins 严重性: CRITICAL 日期: October 30, 2025 影响版本: XI < 2024R1.2 CVE编号: CVE-2024-14003 CWE编号: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVSS评分: 9.4 CVSS V4向量: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H 参考链接: - Nagios XI Security Disclosures - Nagios XI Changelog 发现者: Exodus Intelligence 描述: Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of inbound NRDP request parameters allows crafted input to reach command execution paths, enabling attackers to execute arbitrary commands on the underlying host in the context of the web/Nagios service.