CVE-2013-10072
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
30/10/2025
Last modified:
06/11/2025
Description
Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery results and allowing unintended access to discovery operations.
Impact
Base Score 4.0
7.20
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* | 2011 (including) | |
| cpe:2.3:a:nagios:nagios_xi:2012:r1.0:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2012:r1.1:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2012:r1.2:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2012:r1.3:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2012:r1.4:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2012:r1.5:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



