CVE-2024-13994
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
30/10/2025
Last modified:
06/11/2025
Description
Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized account creation, privilege escalation, or full compromise of the Nagios XI web interface depending on the target account.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* | 2024 (excluding) | |
| cpe:2.3:a:nagios:nagios_xi:2024:r1:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2024:r1.0.1:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2024:r1.0.2:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2024:r1.1:*:*:*:*:*:* | ||
| cpe:2.3:a:nagios:nagios_xi:2024:r1.1.1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



