PT-2025-44499 · Nagios Enterprises · Nagios Xi

Jack Eli

·

Published

2025-10-30

·

Updated

2025-10-31

·

CVE-2024-13996

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.1.3
Description Nagios XI did not properly invalidate all active sessions when a user's password was changed. This allowed existing sessions, potentially compromised, to remain valid after a credential update, enabling continued unauthorized access to user data and actions.
Recommendations Update Nagios XI to version 2024R1.1.3 or later.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14705
CVE-2024-13996

Affected Products

Nagios Xi