CVE-2024-13996: Nagios XI < 2024R1.1.3 Session Not Invalidated After Password Change
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access to user data and actions even after a password change.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13996?
CVE-2024-13996 is classified as a high-severity vulnerability due to the risk of unauthorized access from valid sessions remaining active after a password change.
How do I fix CVE-2024-13996?
To fix CVE-2024-13996, upgrade Nagios XI to version 2024R1.1.3 or later, where the vulnerability has been addressed.
What happens if I do not address CVE-2024-13996?
If CVE-2024-13996 is not addressed, attackers could potentially maintain access to user accounts even after the passwords are changed.
Which versions of Nagios XI are affected by CVE-2024-13996?
CVE-2024-13996 affects all versions of Nagios XI prior to 2024R1.1.3.
Who is at risk from CVE-2024-13996?
Users of Nagios XI who update their passwords without invalidating existing sessions are at risk of having their accounts compromised.