PT-2025-44500 · Nagios Enterprises · Nagios Xi

Publicado

2025-10-30

·

Atualizado

2025-10-31

·

CVE-2024-13999

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.1.3
Description Nagios XI, under certain circumstances, reveals the server's Active Directory (AD) or Lightweight Directory Access Protocol (LDAP) authentication token to a user who is already authenticated. This exposure of the AD/LDAP token could enable unauthorized domain-wide authentication, privilege escalation, or further compromise of network-integrated systems.
Recommendations Update to version 2024R1.1.3 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-14706
CVE-2024-13999

Produtos afetados

Nagios Xi