CVE-2014-8994: Check Diskio Project Check Diskio
Low severity, CVSS 3.6. EPSS: 0.3% chance of exploitation in the next 30 days.
The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).
Affected products
- Check Diskio Project Check Diskio: up to and including 3.2.5
Published 2014-11-28. Last modified 2026-06-17.