Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "Nagios XI could, under certain circumstances, leak the server's AD/LDAP token to an authenticated user."


Workaround

No workaround given by the vendor.

History

Thu, 30 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.
Title Nagios XI < 2024R1.1.3 AD/LDAP Token Authenticated Information Disclosure
Weaknesses CWE-497
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-30T21:28:50.777Z

Reserved: 2025-10-22T17:31:18.123Z

Link: CVE-2024-13999

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-30T22:15:45.180

Modified: 2025-10-30T22:15:45.180

Link: CVE-2024-13999

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.