Nagios XI Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in Nagios XI versions prior to 2024R1.1.2, which may allow authenticated users to access sensitive account information, including API keys and hashed passwords. This issue has been confirmed in versions 2024R1.1 and 2024R1.1.1. The exposure of such information could lead to unauthorized account access, misuse of API privileges, or attempts to crack password hashes offline.

Impact

According to Nagios, this vulnerability could result in unauthorized access to user accounts, allowing for the misuse of API privileges or the cracking of password hashes.

Remediation

Users can upgrade to Nagios XI version 2024R1.1.2 or later to address this vulnerability.

Added: Oct 30, 2025, 10:57 PM
Updated: Oct 30, 2025, 10:57 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.