轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202511-00000041
[內容說明]
研究人員發現Nagios XI存在作業系統指令注入(OS Command Injection)漏洞(CVE-2025-34134、CVE-2025-34284及CVE-2025-34286),未經身分鑑別之遠端攻擊者可注入任意作業系統指令並於伺服器上執行。該漏洞已遭駭客利用,請儘速確認並進行修補。
[影響平台]
CVE-2025-34134漏洞影響為Nagios XI 2024R1.4.2(不含)以前版本
CVE-2025-34284漏洞影響為Nagios XI 2024R2(不含)以前版本
CVE-2025-34286漏洞影響為Nagios XI 2026R1(不含)以前版本
[建議措施]
更新Nagios XI至2026R1(含)以後版本
[參考資料]
1. https://www.nagios.com/products/security/#nagios-xi
2. https://www.cve.org/CVERecord?id=CVE-2025-34134
3. https://www.cve.org/CVERecord?id=CVE-2025-34284
4. https://www.cve.org/CVERecord?id=CVE-2025-34286
Forwarded from National Cybersecurity Information Sharing and Analysis Center: Cybersecurity Alert NISAC-200-202511-00000041
[Content Description]
Researchers have discovered an OS Command Injection vulnerability (CVE-2025-34134, CVE-2025-34284, and CVE-2025-34286) in Nagios XI. An unauthenticated remote attacker could inject arbitrary operating system commands and execute them on the server. This vulnerability has already been exploited by hackers; please confirm and patch it as soon as possible.
[Affected Platforms]
CVE-2025-34134 affects Nagios XI versions prior to 2024R1.4.2.
CVE-2025-34284 affects Nagios XI versions prior to 2024R2.
CVE-2025-34286 affects Nagios XI versions prior to 2026R1.
[Recommended Actions]
Update Nagios XI to 2026R1 or later.
[References]
1. https://www.nagios.com/products/security/#nagios-xi
2. https://www.cve.org/CVERecord?id=CVE-2025-34134
3. https://www.cve.org/CVERecord?id=CVE-2025-34284
4. https://www.cve.org/CVERecord?id=CVE-2025-34286