---
id: CVE-2024-14003
title: "Nagios XI versions prior to 2024R1.2 are\_vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins"
summary: "Nagios XI versions prior to 2024R1.2 are\_vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of inbound NRDP request parameters allows crafted input to reach c…"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: nagios
product: nagios_xi
affected:
  - nagios_xi < 2024
  - nagios_xi = 2024
patched:
  - nagios_xi 2024
published: '2025-10-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:17:56.013'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-14003'
references:
  - url: 'https://www.nagios.com/changelog/nagios-xi/'
    label: disclosure@vulncheck.com
  - url: 'https://www.nagios.com/products/security/#nagios-xi'
    label: disclosure@vulncheck.com
  - url: 'https://www.vulncheck.com/advisories/nagios-xi-rce-via-nrdp-server-plugins'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.02297
epssPercentile: 0.82627
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-10-31T13:05:41.149998Z'
scores:
  nvd: 9.8
  cna: 9.4
ingestedAt: '2026-09-30T18:17:24.564Z'
---

## Overview

Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of inbound NRDP request parameters allows crafted input to reach command execution paths, enabling attackers to execute arbitrary commands on the underlying host in the context of the web/Nagios service.

## Affected

- `nagios_xi < 2024`
- `nagios_xi = 2024`

## Remediation

Upgrade past the affected range:

- `nagios_xi 2024`
