Vulnerability Description
Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized account creation, privilege escalation, or full compromise of the Nagios XI web interface depending on the target account.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nagios | Nagios Xi | < 2024 |
Related Weaknesses (CWE)
References
- https://www.nagios.com/changelog/nagios-xi/Release Notes
- https://www.nagios.com/products/security/#nagios-xiVendor Advisory
- https://www.vulncheck.com/advisories/nagios-xi-allow-insecure-logins-missing-autThird Party Advisory
FAQ
What is CVE-2024-13994?
CVE-2024-13994 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials...
How severe is CVE-2024-13994?
CVE-2024-13994 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-13994?
Check the references section above for vendor advisories and patch information. Affected products include: Nagios Nagios Xi.