CVE-2024-13998
Nagios XI vulnerability analysis and mitigation

Overview

CVE-2024-13998 is an information disclosure vulnerability in Nagios XI that allows authenticated users with low privileges to access sensitive user account data — including API keys and hashed passwords — that they should not be permitted to view. It affects Nagios XI versions prior to 2024R1.1.3, including all 2024R1.x releases up through 2024R1.1.2. The vulnerability was published on November 3, 2025, with an initial analysis by NIST completed on November 6, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 6.0 (Medium) (Feedly, VulnCheck Advisory). A related vulnerability, CVE-2024-13995, addressed a similar issue but with a potentially incomplete fix in earlier versions (Feedly).

Technical details

The root cause is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), where Nagios XI fails to properly enforce access controls on certain data endpoints, allowing authenticated low-privileged users to retrieve sensitive account information under specific circumstances. The attack vector is network-based and requires only low-level authentication with no user interaction, though the CVSS v4.0 scoring notes that attack requirements (AT:P) indicate certain preconditions must be met for exploitation. The exposed data includes plaintext API keys and hashed passwords, which can be leveraged for privilege escalation or offline password cracking. No specific technical write-up or public proof-of-concept code has been identified at this time (VulnCheck Advisory, Feedly).

Impact

Successful exploitation allows a low-privileged authenticated attacker to obtain API keys and hashed passwords belonging to other user accounts, including potentially administrative accounts. Exposed API keys could be abused to perform unauthorized actions within Nagios XI, while hashed passwords are susceptible to offline cracking attacks that could yield plaintext credentials. This creates a realistic path to account compromise and privilege escalation within the monitoring infrastructure, which often has broad network visibility and access to sensitive host and service configurations (Feedly, VulnCheck Advisory).

Exploitability

As of the time of publication, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.82%, indicating a low probability of exploitation in the near term. No threat actor attribution has been reported (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible Nagios XI instances running versions prior to 2024R1.1.3 using network scanning tools or Shodan queries targeting Nagios XI login pages.
  2. Obtain low-privileged credentials: Acquire or register a low-privileged authenticated account on the target Nagios XI instance.
  3. Identify vulnerable endpoint: Authenticate to the Nagios XI web interface and identify the specific API or administrative endpoint that improperly exposes user account data (the exact endpoint is not publicly documented).
  4. Extract sensitive data: Under the specific circumstances that trigger the disclosure, retrieve the response containing API keys and hashed passwords of other user accounts.
  5. Leverage exposed credentials: Use obtained API keys directly to make authenticated API calls with elevated privileges, or submit hashed passwords to offline cracking tools (e.g., Hashcat, John the Ripper) to recover plaintext credentials for further account compromise (VulnCheck Advisory, Feedly).

Indicators of compromise

  • Logs: Nagios XI access logs showing low-privileged user accounts making repeated or unusual requests to user management or API endpoints; unexpected API calls authenticated with credentials belonging to other users.
  • Network: Outbound API requests from the Nagios XI server using API keys not associated with the originating session; unusual API activity patterns from non-administrative accounts.
  • Application: Evidence of API key usage from unexpected IP addresses or at unusual times; multiple failed or successful authentication attempts using credentials that were recently exposed; new administrative actions performed by accounts that should not have elevated access.

Mitigation and workarounds

Nagios has released version 2024R1.1.3 as the patched release that resolves this vulnerability; all users should upgrade immediately (Nagios Security, Nagios Changelog). No specific configuration-based workaround has been published. Post-patching, administrators should rotate all API keys, reset user passwords, audit user permissions to enforce least privilege, and review logs for any signs of unauthorized data access prior to patching (Feedly).

Additional resources


SourceThis report was generated using AI

Related Nagios XI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-2043HIGH8.8
  • Nagios XI logoNagios XI
  • cpe:2.3:a:nagios:nagios_xi
NoNoFeb 20, 2026
CVE-2026-2042HIGH8.8
  • Nagios XI logoNagios XI
  • cpe:2.3:a:nagios:nagios_xi
NoNoFeb 20, 2026
CVE-2026-2041HIGH8.8
  • Nagios XI logoNagios XI
  • cpe:2.3:a:nagios:nagios_xi
NoNoFeb 20, 2026
CVE-2025-67255HIGH8.8
  • Nagios XI logoNagios XI
  • cpe:2.3:a:nagios:nagios_xi
NoNoDec 29, 2025
CVE-2025-67254HIGH7.5
  • Nagios XI logoNagios XI
  • cpe:2.3:a:nagios:nagios_xi
NoNoDec 29, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management