# CVE-2024-13997

## Summary

- **CVE ID:** CVE-2024-13997
- **Severity:** CRITICAL
- **CVSS Score:** 9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-269
- **Published:** Nov 3, 2025
- **Last Modified:** Mar 13, 2026

## Description

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.

## Affected Products

- Nagios — XI (0)

## References

- [CNA](https://www.nagios.com/products/security/#nagios-xi)
- [CNA](https://www.nagios.com/changelog/nagios-xi/)
- [CNA](https://www.vulncheck.com/advisories/nagios-xi-privilege-escalation-via-migrate-server-feature-to-root-on-host)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.13%
- **EPSS Percentile:** 64.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._