CVE-2014-8994: Check Diskio Project Check Diskio

Low severity, CVSS 3.6. EPSS: 0.3% chance of exploitation in the next 30 days.

The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).

Affected products

Published 2014-11-28. Last modified 2026-06-17.