Vulnerability Description
Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nagios | Nagios Xi | < 2024 |
Related Weaknesses (CWE)
References
- https://www.nagios.com/changelog/nagios-xi/Release Notes
- https://www.nagios.com/products/security/#nagios-xiVendor Advisory
- https://www.vulncheck.com/advisories/nagios-xi-ad-ldap-token-authenticated-inforThird Party Advisory
FAQ
What is CVE-2024-13999?
CVE-2024-13999 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP...
How severe is CVE-2024-13999?
CVE-2024-13999 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-13999?
Check the references section above for vendor advisories and patch information. Affected products include: Nagios Nagios Xi.