Impact
The Nagios XI function is_insecure_login_authenticated uses an insecure timing comparison, allowing an attacker to measure response times during authentication attempts. This side‑channel information enables a brute‑force attack that can guess the admin password by exploiting timing differences in an otherwise correct password check.
Affected Systems
All Nagios XI installations version 5.9.2 and earlier are affected. Nagios XI must be updated to 5.9.3 or later to contain the fixed comparison routine.
Risk and Exploitability
The CVSS score of 3.5 indicates a low severity for the vulnerability; however, the lack of an EPSS score and its absence from the CISA KEV catalog do not negate the feasibility of exploitation. Attackers can perform remote brute‑force attempts from outside the internal network by repeatedly invoking the login function and measuring response latency to infer correct password characters. No local privileges or advanced techniques are required beyond network connectivity and timing analysis.
OpenCVE Enrichment