Nagios XI
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*
- < 2024R1.1.2
A vulnerability exists in Nagios XI versions prior to 2024R1.1.2, where the 'Allow Insecure Logins' option can be enabled without proper authorization controls. This flaw allows users to create valid login credentials for other users, potentially leading to unauthorized account creation, privilege escalation, or a complete compromise of the Nagios XI web interface, depending on the account in question.
Exploitation of this vulnerability could result in unauthorized account creation, privilege escalation, or full compromise of the Nagios XI web interface, depending on the target account.
Users can upgrade to Nagios XI version 2024R1.1.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.