CVE-2024-13998: Nagios XI < 2024R1.1.3 API Keys & Hashed Passwords Authenticated Information Disclosure
Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts. CVE-2024-13995 addresses a similar vulnerability with a potentially incomplete fix for the underlying problem in earlier versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13998?
The severity of CVE-2024-13998 is classified as high due to the potential exposure of sensitive user account information.
How do I fix CVE-2024-13998?
To fix CVE-2024-13998, upgrade Nagios XI to version 2024R1.1.3 or later.
Who is affected by CVE-2024-13998?
CVE-2024-13998 affects all users of Nagios XI versions prior to 2024R1.1.3.
What data is disclosed in CVE-2024-13998?
CVE-2024-13998 discloses sensitive user account information, including API keys and hashed passwords.
Can CVE-2024-13998 lead to further attacks?
Yes, the exposure of API keys and password hashes in CVE-2024-13998 can lead to account compromise and other security incidents.