
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-13998 is an information disclosure vulnerability in Nagios XI that allows authenticated users with low privileges to access sensitive user account data — including API keys and hashed passwords — that they should not be permitted to view. It affects Nagios XI versions prior to 2024R1.1.3, including all 2024R1.x releases up through 2024R1.1.2. The vulnerability was published on November 3, 2025, with an initial analysis by NIST completed on November 6, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 6.0 (Medium) (Feedly, VulnCheck Advisory). A related vulnerability, CVE-2024-13995, addressed a similar issue but with a potentially incomplete fix in earlier versions (Feedly).
The root cause is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), where Nagios XI fails to properly enforce access controls on certain data endpoints, allowing authenticated low-privileged users to retrieve sensitive account information under specific circumstances. The attack vector is network-based and requires only low-level authentication with no user interaction, though the CVSS v4.0 scoring notes that attack requirements (AT:P) indicate certain preconditions must be met for exploitation. The exposed data includes plaintext API keys and hashed passwords, which can be leveraged for privilege escalation or offline password cracking. No specific technical write-up or public proof-of-concept code has been identified at this time (VulnCheck Advisory, Feedly).
Successful exploitation allows a low-privileged authenticated attacker to obtain API keys and hashed passwords belonging to other user accounts, including potentially administrative accounts. Exposed API keys could be abused to perform unauthorized actions within Nagios XI, while hashed passwords are susceptible to offline cracking attacks that could yield plaintext credentials. This creates a realistic path to account compromise and privilege escalation within the monitoring infrastructure, which often has broad network visibility and access to sensitive host and service configurations (Feedly, VulnCheck Advisory).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.82%, indicating a low probability of exploitation in the near term. No threat actor attribution has been reported (Feedly).
Nagios has released version 2024R1.1.3 as the patched release that resolves this vulnerability; all users should upgrade immediately (Nagios Security, Nagios Changelog). No specific configuration-based workaround has been published. Post-patching, administrators should rotate all API keys, reset user passwords, audit user permissions to enforce least privilege, and review logs for any signs of unauthorized data access prior to patching (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."