Vulnerability record · CVE-2024-24401 · published 26 February 2024
CVE-2024-24401: Nagios XI monitoringwizard.php SQL injection allows remote code execution
Nagios · Nagios Xi
Nagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to arbitrary code execution on the affected server. Because the flaw is network reachable and needs no credentials, it is a serious risk to exposed Nagios XI installations.
Description
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a high EPSS score make this a top remediation priority despite no KEV listing.
What it is
Nagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to arbitrary code execution on the affected server. Because the flaw is network reachable and needs no credentials, it is a serious risk to exposed Nagios XI installations.
Impact
An attacker can execute arbitrary code on the Nagios XI host, gaining control of the monitoring server and potentially pivoting to systems it manages.
Attack surface
Reached over the network through the monitoringwizard.php component; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at roughly 0.46 (98.7th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Nagios XI to a version later than 2024R1.01 per the vendor changelog.
- Restrict network access to the Nagios XI web interface to trusted management networks.
- Enforce authentication and least privilege on the Nagios XI application and its database account.
- Monitor the vendor changelog and advisories for the fixed release and apply it promptly.
Detection
- Review web server and Nagios XI logs for suspicious requests to monitoringwizard.php, especially SQL metacharacters or encoded payloads.
- Alert on unexpected child processes or command execution spawned by the Nagios XI web or database service.
- Baseline and monitor database queries from the Nagios XI application for anomalous SQL patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.nagios.com/changelog/ | Release Notes |
| https://www.nagios.com/changelog/ | Release Notes |
Track CVE-2024-24401 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-24401), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.