Description
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.
Related CPE's
a
nagios
nagios_xi
14
Weaknesses
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-79
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
9.1 · Critical
Information
Source identifier
Vulnerability status
Analyzed
Published
2024-10-14T17:15:10.780Z
1 year agoLast modified
2025-07-10T15:06:27.267Z
8 months ago