Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "Nagios XI 2024R1.1 and 2024R1.1.1 will leak user account information (including API keys and hashed passwords) to authenticated users."


Workaround

No workaround given by the vendor.

History

Thu, 30 Oct 2025 21:45:00 +0000

Type Values Removed Values Added
Description Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts.
Title Nagios XI < 2024R1.1.2 API Keys & Hashed Passwords Authenticated Information Disclosure
Weaknesses CWE-497
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-30T21:29:55.745Z

Reserved: 2025-10-22T16:55:15.925Z

Link: CVE-2024-13995

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-30T22:15:44.903

Modified: 2025-10-30T22:15:44.903

Link: CVE-2024-13995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.