Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.
History

Fri, 31 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios xi
Vendors & Products Nagios
Nagios xi

Thu, 30 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.
Title Nagios XI < 2024R1.1.3 AD/LDAP Token Authenticated Information Disclosure
Weaknesses CWE-497
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-10-30T21:28:50.777Z

Updated: 2025-10-31T15:08:00.594Z

Reserved: 2025-10-22T17:31:18.123Z

Link: CVE-2024-13999

cve-icon Vulnrichment

Updated: 2025-10-31T15:07:56.239Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-30T22:15:45.180

Modified: 2025-11-04T15:41:56.843

Link: CVE-2024-13999

cve-icon Redhat

No data.