CVE-2011-10035 Details
Description
Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions and missing synchronization or final-path validation, a local low-privileged user could manipulate filesystem state during crontab installation to influence the files or commands executed with elevated privileges, resulting in execution with higher privileges.
A privilege escalation vulnerability has been identified in Nagios XI versions prior to 2011R1.9. The issue arises from race conditions and inadequate validation in the scripts that manage system crontab entries. A local user with low privileges could exploit these vulnerabilities by manipulating the filesystem state during the crontab installation process. This manipulation could influence the execution of files or commands with elevated privileges, leading to unauthorized access or actions.
Users can upgrade to Nagios XI version 2011R1.9 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nagios.com/changelog/nagios-xi/ | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/nagios-xi-race-conditions-in-crontab-install-script-lpe | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nagios nagios xi | <= 2009 2011 r1 2011 r1.1 2011 r1.2 2011 r1.3 2011 r1.4 2011 r1.5 2011 r1.6 2011 r1.7 2011 r1.8 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Nov 6, 2025 | Initial Analysis | [email protected] |
| Oct 30, 2025 | New CVE Received | [email protected] |