PT-2025-44497 · Nagios Enterprises · Nagios Xi
CVE-2024-13994
·
Publicado
2025-10-30
·
Atualizado
2025-10-31
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 2024R1.1.2
Description
Nagios XI versions prior to 2024R1.1.2 have a flaw where authorization checks are absent when the 'Allow Insecure Logins' option is active. This allows any user to generate valid login credentials for other users without the necessary permissions. Successful exploitation could result in unauthorized account creation, privilege escalation, or complete compromise of the Nagios XI web interface, depending on the targeted account.
Recommendations
Update Nagios XI to version 2024R1.1.2 or later.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nagios Xi