Impact
The Nagios XI function is_insecure_login_authenticated uses an insecure timing comparison (CWE‑208), allowing an attacker to measure response times during authentication attempts. This side‑channel information enables a brute‑force attack that can guess the admin password by exploiting timing differences in an otherwise correct password check.
Affected Systems
Based on the description it is inferred that all Nagios XI installations version 5.9.2 and earlier are affected. Nagios XI must be updated to 5.9.3 or later to contain the fixed comparison routine.
Risk and Exploitability
The CVSS score of 3.5 indicates low severity. The EPSS score is reported as less than 1 %, suggesting a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Even so, an attacker with remote network access could launch a brute‑force attack by measuring timing differences to determine correct password characters. No special privileges or local access are required beyond network connectivity to the login interface.
OpenCVE Enrichment