CVE-2024-13999

CRITICAL

Nagios XI <2024R1.1.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.

Scores

CVSS v3 9.8
EPSS 0.0084
EPSS Percentile 74.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (2)
nagios/nagios_xi 2024 r1 (6 CPE variants)
nagios/nagios_xi < 2024
Published Oct 30, 2025
Tracked Since Feb 18, 2026