CVE-2011-10035 describes privilege escalation vulnerabilities in Nagios XI versions prior to 2011R1.9. A local, low-privileged user could exploit time-of-check/time-of-use race conditions during crontab installation to execute arbitrary commands with elevated privileges. With a CVSS score of 7.0 (HIGH), this vulnerability has a high impact on confidentiality, integrity, and availability, but requires high attack complexity. There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2009CPE matchmatch criteria | cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* | ||
2011CPE matchmatch criteria | cpe:2.3:a:nagios:nagios_xi:2011:r1:*:*:*:*:*:* | ||
2011CPE matchmatch criteria | cpe:2.3:a:nagios:nagios_xi:2011:r1.1:*:*:*:*:*:* | ||
2011CPE matchmatch criteria | cpe:2.3:a:nagios:nagios_xi:2011:r1.2:*:*:*:*:*:* | ||
2011CPE matchmatch criteria | cpe:2.3:a:nagios:nagios_xi:2011:r1.3:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.