{"id":"CVE-2024-13997","title":"Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host","summary":"Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the mig…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"vendor":"nagios","product":"nagios_xi","affected":["nagios_xi < 2024","nagios_xi = 2024"],"patched":["nagios_xi 2024"],"published":"2025-11-03","updated":"2026-09-26","sourceUpdated":"2026-09-26T21:10:00.130","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-13997","references":[{"url":"https://www.nagios.com/changelog/nagios-xi/","label":"disclosure@vulncheck.com"},{"url":"https://www.nagios.com/products/security/#nagios-xi","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/nagios-xi-privilege-escalation-via-migrate-server-feature-to-root-on-host","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.01129,"epssPercentile":0.65021,"ingestedAt":"2026-09-26T21:38:01.487Z","slug":"CVE-2024-13997","body":"## Overview\n\nNagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.\n\n## Affected\n\n- `nagios_xi < 2024`\n- `nagios_xi = 2024`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `nagios_xi 2024`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}