PT-2025-44497 · Nagios Enterprises · Nagios Xi

CVE-2024-13994

·

Publicado

2025-10-30

·

Atualizado

2025-10-31

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2024R1.1.2
Description Nagios XI versions prior to 2024R1.1.2 have a flaw where authorization checks are absent when the 'Allow Insecure Logins' option is active. This allows any user to generate valid login credentials for other users without the necessary permissions. Successful exploitation could result in unauthorized account creation, privilege escalation, or complete compromise of the Nagios XI web interface, depending on the targeted account.
Recommendations Update Nagios XI to version 2024R1.1.2 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-14704
CVE-2024-13994

Produtos afetados

Nagios Xi