CVE-2025-34134 Details
Description
Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization of administrator-controlled BPI configuration parameters (notably bpi_logfile and bpi_configfile) allow an authenticated administrative user to cause the product to create or overwrite files within the webroot and subsequently edit them via the BPI configuration editor. When such files carry executable extensions and are served by the web application, arbitrary code may be executed in the context of the web application user. Successful exploitation results in arbitrary command execution with the privileges of the Nagios XI web application user and can be leveraged to gain further control of the underlying host operating system.
A remote code execution vulnerability exists in Nagios XI versions prior to 2024R1.4.2, specifically within the Business Process Intelligence (BPI) component. This vulnerability arises from inadequate validation and sanitization of BPI configuration parameters controlled by administrators, particularly 'bpi_logfile' and 'bpi_configfile'. An authenticated administrative user can exploit this flaw to create or overwrite files in the webroot, which can then be edited using the BPI configuration editor. If these files have executable extensions and are served by the web application, arbitrary code could be executed as the Nagios XI web application user, potentially leading to further control over the host operating system.
Users can upgrade to Nagios XI version 2024R1.4.2 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nagios.com/changelog/nagios-xi/ | [email protected] | Release Notes |
| https://www.nagios.com/products/security/#nagios-xi | [email protected] | Vendor Advisory |
| https://www.vulncheck.com/advisories/nagios-xi-rce-via-business-process-intelligence-bpi | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nagios nagios xi | < 2024 2024 r1 2024 r1.0.1 2024 r1.0.2 2024 r1.1 2024 r1.1.1 2024 r1.1.2 2024 r1.1.3 2024 r1.1.4 2024 r1.1.5 2024 r1.2 2024 r1.2.1 2024 r1.2.2 2024 r1.3 2024 r1.3.1 2024 r1.3.2 2024 r1.3.3 2024 r1.3.4 2024 r1.4 2024 r1.4.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 6, 2025 | Initial Analysis | [email protected] |
| Oct 30, 2025 | New CVE Received | [email protected] |