
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-13995 is a sensitive information disclosure vulnerability in Nagios XI that allows authenticated users with low privileges to access sensitive user account data they should not be permitted to view. The vulnerability is confirmed in Nagios XI versions 2024R1.1 and 2024R1.1.1, and affects all versions prior to 2024R1.1.2. It was published on October 30, 2025, and assigned by VulnCheck. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.1 (High) (Nagios Security, VulnCheck Advisory).
The root cause is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), where the application improperly exposes sensitive user account data — including API keys and hashed passwords — to authenticated users who lack authorization to access that information. The attack vector is network-based, requires low privileges (a valid authenticated session), no user interaction, and low attack complexity, making it straightforward to exploit once an attacker has any valid account. The vulnerability likely stems from insufficient access control enforcement on API endpoints or administrative data views that return more user account information than the requesting user's role should permit (VulnCheck Advisory, Nagios Changelog).
Successful exploitation allows a low-privileged authenticated attacker to obtain API keys belonging to other users (including potentially administrative accounts) and hashed passwords, which can be used for unauthorized API access, privilege escalation, or offline password cracking attempts. Compromised API keys could enable an attacker to perform actions on behalf of higher-privileged users, potentially leading to full system compromise of the Nagios XI monitoring infrastructure. Given that Nagios XI typically has visibility into and credentials for a broad range of monitored network infrastructure, a compromise of this system could facilitate significant lateral movement across an organization's environment (VulnCheck Advisory).
There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (VulnCheck Advisory). The EPSS score is approximately 0.44%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.
The primary remediation is to upgrade Nagios XI to version 2024R1.1.2 or later, which addresses the improper access control allowing unauthorized disclosure of sensitive account data (Nagios Security, Nagios Changelog). After upgrading, administrators should immediately rotate all API keys and reset user passwords as a precautionary measure, since exposure may have occurred in affected versions. Additionally, implement strict least-privilege access controls, limit the number of accounts with access to the Nagios XI interface, and monitor for any signs of unauthorized API usage or account access.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."