CVE-2024-54961
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
20/02/2025
Last modified:
18/06/2025
Description
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nagios:nagios_xi:2024:r1.2.2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



