CVE-2024-13994
Last modified
CVE-2024-13994 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized account creation, privilege escalation, or full compromise of the Nagios XI web interface depending on the target account.. EPSS estimates a 0.84% chance of exploitation in the next 30 days.
Description
Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized account creation, privilege escalation, or full compromise of the Nagios XI web interface depending on the target account.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Nagios | Nagios Xi | < 2024 | — |
| Nagios | Nagios Xi | 2024 | R1 |
References
- https://www.nagios.com/changelog/nagios-xi/Release Notes
- https://www.nagios.com/products/security/#nagios-xiVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-13994?
How severe is CVE-2024-13994?
How do I fix CVE-2024-13994?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-13987Improper neutralization of input during web page generation …5.9
- CVE-2024-1399The Restaurant Menu – Food Ordering System – Table Reservati…6.4
- CVE-2024-13990MicroWorld eScan AV's update mechanism failed to ensure auth…9.3
- CVE-2024-13991Huijietong Cloud Video Platform contains a path traversal vu…8.7
- CVE-2024-13992Nagios XI versions prior to < 2024R1.1 is vulnerable to a cr…5.4
- CVE-2024-13993Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a…6.1
- CVE-2024-13995Nagios XI versions prior to 2024R1.1.2 may (confirmed in 202…8.8
- CVE-2024-13996Nagios XI versions prior to 2024R1.1.3 did not invalidate al…9.8
- CVE-2024-13997Nagios XI versions prior to 2024R1.1.3 contain a privilege e…7.2
- CVE-2024-13998Nagios XI versions prior to 2024R1.1.3, under certain circum…6.5
- CVE-2024-13999Nagios XI versions prior to 2024R1.1.3, under certain circum…9.8
- CVE-2024-1400The Mollie Forms plugin for WordPress is vulnerable to unaut…4.3
Are you affected by CVE-2024-13994?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
