Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts.
                
            Metrics
Affected Vendors & Products
Advisories
    No advisories yet.
Fixes
    Solution
Nagios addresses this vulnerability as "Nagios XI 2024R1.1 and 2024R1.1.1 will leak user account information (including API keys and hashed passwords) to authenticated users."
Workaround
No workaround given by the vendor.
References
        History
                    Thu, 30 Oct 2025 21:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts. | |
| Title | Nagios XI < 2024R1.1.2 API Keys & Hashed Passwords Authenticated Information Disclosure | |
| Weaknesses | CWE-497 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-10-30T21:29:55.745Z
Reserved: 2025-10-22T16:55:15.925Z
Link: CVE-2024-13995
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Received
Published: 2025-10-30T22:15:44.903
Modified: 2025-10-30T22:15:44.903
Link: CVE-2024-13995
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.