Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions and missing synchronization or final-path validation, a local low-privileged user could manipulate filesystem state during crontab installation to influence the files or commands executed with elevated privileges, resulting in execution with higher privileges.
Conclusion & alert: CVE-2011-10035 is rated Low Risk (29.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.01%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-10-31 | — | 0.01% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 4.0 | HIGH |
|
— | — | [email protected] |
| 7.0 | 3.1 | HIGH |
|
1.0 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| nagios | nagios_xi | <= 2009 | cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* |
| nagios | nagios_xi | 2011 | cpe:2.3:a:nagios:nagios_xi:2011:r1:*:*:*:*:*:* |
| nagios | nagios_xi | 2011 | cpe:2.3:a:nagios:nagios_xi:2011:r1.1:*:*:*:*:*:* |
| nagios | nagios_xi | 2011 | cpe:2.3:a:nagios:nagios_xi:2011:r1.2:*:*:*:*:*:* |
| nagios | nagios_xi | 2011 | cpe:2.3:a:nagios:nagios_xi:2011:r1.3:*:*:*:*:*:* |
| nagios | nagios_xi | 2011 | cpe:2.3:a:nagios:nagios_xi:2011:r1.4:*:*:*:*:*:* |
| nagios | nagios_xi | 2011 | cpe:2.3:a:nagios:nagios_xi:2011:r1.5:*:*:*:*:*:* |
| nagios | nagios_xi | 2011 | cpe:2.3:a:nagios:nagios_xi:2011:r1.6:*:*:*:*:*:* |
| nagios | nagios_xi | 2011 | cpe:2.3:a:nagios:nagios_xi:2011:r1.7:*:*:*:*:*:* |
| nagios | nagios_xi | 2011 | cpe:2.3:a:nagios:nagios_xi:2011:r1.8:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.nagios.com/changelog/nagios-xi/ | Release Notes |
| https://www.vulncheck.com/advisories/nagios-xi-race-conditions-in-crontab-install-script-lpe | Third Party Advisory |