PT-2024-13539 · Nagios Xi · Nagios Xi

Published

2024-10-14

·

Updated

2025-07-10

·

CVE-2023-48082

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1 Nagios XI versions prior to 5.11.3 2024R1
Description The issue is related to the improper handling of API keys generation in Nagios XI, allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate. This could potentially enable unauthorized access.
Recommendations For Nagios XI versions prior to 2024R1, upgrade to Nagios XI 2024R1 or later to address this issue. For Nagios XI versions prior to 5.11.3 2024R1, upgrade to Nagios XI 5.11.3 2024R1 or later to address this issue. As a temporary workaround, consider restricting access to API endpoints that utilize the generated API keys until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-48082

Affected Products

Nagios Xi