← Back

CVE-2024-13998

nvd nist
Published: Nov 3, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.0
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)

Description

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts. CVE-2024-13995 addresses a similar vulnerability with a potentially incomplete fix for the underlying problem in earlier versions.

Affected (7)

Products: Nagios: Nagios Xi
1 product
Nagios Xi
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Nagios
Before 2024
Version 2024 r1.0.1
Version 2024 r1.0.2
Version 2024 r1.1.1
Version 2024 r1.1.2
Version 2024 r1.1
Version 2024 r1

References (3)

Source: disclosure@vulncheck.com
Release Notes
Source: disclosure@vulncheck.com
Vendor Advisory

Timeline

No history available yet.