CVE-2025-34134 | Nagios XI up to 2024R1.4.1 Business Process Intelligence bpi_logfile/bpi_configfile os command injection (WID-SEC-2025-2459)
A vulnerability, which was classified as critical, was found in Nagios XI up to 2024R1.4.1. Affected is an unknown function of the component Business Process Intelligence. Such manipulation of the argument bpi_logfile/bpi_configfile leads to os command injection.
This vulnerability is documented as CVE-2025-34134. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.