PT-2025-44801 · Nagios Enterprises · Nagios Xi

Published

2024-05-28

·

Updated

2025-11-04

·

CVE-2024-13998

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.1.3
Description Nagios XI may disclose sensitive user account information, including API keys and hashed passwords, to authenticated users who lack the necessary permissions. This exposure could lead to account compromise, misuse of API privileges, or attempts to crack passwords offline. The issue relates to unauthorized access to protected information within the IT infrastructure monitoring tool.
Recommendations Update to version 2024R1.1.3 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-14478
CVE-2024-13998

Affected Products

Nagios Xi