PT-2025-44500 · Nagios Enterprises · Nagios Xi

Published

2025-10-30

·

Updated

2025-10-31

·

CVE-2024-13999

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.1.3
Description Nagios XI, under certain circumstances, reveals the server's Active Directory (AD) or Lightweight Directory Access Protocol (LDAP) authentication token to a user who is already authenticated. This exposure of the AD/LDAP token could enable unauthorized domain-wide authentication, privilege escalation, or further compromise of network-integrated systems.
Recommendations Update to version 2024R1.1.3 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-14706
CVE-2024-13999

Affected Products

Nagios Xi