【資安漏洞預警】Nagios XI存在高風險安全漏洞(CVE-2025-34134、CVE-2025-34284及CVE-2025-34286),請儘速確認並進行修補
[Security Vulnerability Alert] Nagios XI contains high-risk security vulnerabilities (CVE-2025-34134, CVE-2025-34284, and CVE-2025-34286). Please confirm and patch them as soon as possible.

發布單位:圖資處數位服務組
日期範圍:2025/11/7 ~ 2026/5/7
 
發布單位:圖資處數位服務組
日期範圍:2025/11/7 ~ 2026/5/7
行政 行政公告
全體

轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202511-00000041

[內容說明]
研究人員發現Nagios XI存在作業系統指令注入(OS Command Injection)漏洞(CVE-2025-34134、CVE-2025-34284及CVE-2025-34286),未經身分鑑別之遠端攻擊者可注入任意作業系統指令並於伺服器上執行。該漏洞已遭駭客利用,請儘速確認並進行修補。

[影響平台]
CVE-2025-34134漏洞影響為Nagios XI 2024R1.4.2(不含)以前版本
CVE-2025-34284漏洞影響為Nagios XI 2024R2(不含)以前版本
CVE-2025-34286漏洞影響為Nagios XI 2026R1(不含)以前版本

[建議措施]
更新Nagios XI至2026R1(含)以後版本

[參考資料]
1. https://www.nagios.com/products/security/#nagios-xi
2. https://www.cve.org/CVERecord?id=CVE-2025-34134
3. https://www.cve.org/CVERecord?id=CVE-2025-34284
4. https://www.cve.org/CVERecord?id=CVE-2025-34286

Forwarded from National Cybersecurity Information Sharing and Analysis Center: Cybersecurity Alert NISAC-200-202511-00000041

[Content Description]
Researchers have discovered an OS Command Injection vulnerability (CVE-2025-34134, CVE-2025-34284, and CVE-2025-34286) in Nagios XI. An unauthenticated remote attacker could inject arbitrary operating system commands and execute them on the server. This vulnerability has already been exploited by hackers; please confirm and patch it as soon as possible.

[Affected Platforms]
CVE-2025-34134 affects Nagios XI versions prior to 2024R1.4.2.
CVE-2025-34284 affects Nagios XI versions prior to 2024R2.
CVE-2025-34286 affects Nagios XI versions prior to 2026R1.

[Recommended Actions]
Update Nagios XI to 2026R1 or later.

[References]
1. https://www.nagios.com/products/security/#nagios-xi
2. https://www.cve.org/CVERecord?id=CVE-2025-34134
3. https://www.cve.org/CVERecord?id=CVE-2025-34284
4. https://www.cve.org/CVERecord?id=CVE-2025-34286


相關附件
Top↑