Nagios XI < 2024R1.1.3 API Keys & Hashed Passwords Authenticated Information Disclosure
Summary
| CVE | CVE-2024-13998 |
|---|---|
| State | PUBLISHED |
| Assigner | VulnCheck |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-11-03 22:16:40 UTC |
| Updated | 2026-09-26 21:10:00 UTC |
| Description | Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts. CVE-2024-13995 addresses a similar vulnerability with a potentially incomplete fix for the underlying problem in earlier versions. |
Risk And Classification
Primary CVSS: v4.0 6 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.009700000 probability, percentile 0.604290000 (date 2026-09-29)
Problem Types: CWE-497 | CWE-497 CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nagios | Nagios Xi | All | All | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.0.1 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.0.2 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.1 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.1.1 | All | All |
| Application | Nagios | Nagios Xi | 2024 | r1.1.2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.nagios.com/changelog/nagios-xi | [email protected] | www.nagios.com | Release Notes |
| www.vulncheck.com/advisories/nagios-xi-api-keys-and-hashed-password-authenticat... | [email protected] | www.vulncheck.com | Third Party Advisory |
| www.nagios.com/products/security | [email protected] | www.nagios.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
Solutions
CNA: Nagios addresses this vulnerability as "Nagios XI could, under certain circumstances, leak other users' API tokens or hashed passwords to other authenticated users."