CVE-2024-13994: Nagios XI < 2024R1.1.2 Allow Insecure Logins Missing Authorization
Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized account creation, privilege escalation, or full compromise of the Nagios XI web interface depending on the target account.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13994?
CVE-2024-13994 is classified as a high severity vulnerability due to its potential for unauthorized account access.
How do I fix CVE-2024-13994?
To fix CVE-2024-13994, upgrade Nagios XI to version 2024R1.1.2 or later.
What does the 'Allow Insecure Logins' option do in Nagios XI related to CVE-2024-13994?
The 'Allow Insecure Logins' option allows users to bypass authorization checks, enabling them to create login credentials for other users without proper permissions.
What versions of Nagios XI are affected by CVE-2024-13994?
CVE-2024-13994 affects all versions of Nagios XI prior to 2024R1.1.2.
What are the consequences of not addressing CVE-2024-13994?
Not addressing CVE-2024-13994 can lead to unauthorized access to user accounts, compromising the security of the Nagios XI deployment.