CVE-2024-13999: high-severity vulnerability in Nagios XI
Nagios XI < 2024R1.1.3 AD/LDAP Token Authenticated Information Disclosure
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.3epss 1.9%
exploitation probability
1.9%top 21% of all CVEs
observed exploitation
nono source reports it
Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Affected products
Nagios · XIRelated CVEs — Nagios XI
In the same product, most dangerous first.
CVE-2024-14005CRITICALNagios XI < 2024R1.2 Command Injection via Docker WizardEPSS 4.0%CVE-2025-34284CRITICALNagios XI < 2024R2 Authenticated Command Injection via WinRM PluginEPSS 4.0%CVE-2013-10073HIGHNagios XI < 2012R1.6 Auto-Discovery Shell Command InjectionEPSS 3.4%CVE-2020-36867HIGHNagios XI < 5.7.3 Command Injection in Report PDF DownloadEPSS 2.5%CVE-2020-36856CRITICALNagios XI < 5.6.14 Authenticated RCE command_test.php via addressEPSS 2.5%CVE-2024-14008CRITICALNagios XI < 2024R1.3.2 RCE via WinRM Configuration WizardEPSS 2.4%