PT-2025-44801 · Nagios Enterprises · Nagios Xi
Published
2024-05-28
·
Updated
2025-11-04
·
CVE-2024-13998
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 2024R1.1.3
Description
Nagios XI may disclose sensitive user account information, including API keys and hashed passwords, to authenticated users who lack the necessary permissions. This exposure could lead to account compromise, misuse of API privileges, or attempts to crack passwords offline. The issue relates to unauthorized access to protected information within the IT infrastructure monitoring tool.
Recommendations
Update to version 2024R1.1.3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Xi