CVE-2024-13999

🟠 Łataj w tym tygodniu

Ujawnienie tokena AD/LDAP w Nagios XI umożliwia nadużycie uwierzytelnienia i eskalację uprawnień.

CVSS
9.8
EPSS
1.8%
Exploit
none
Vendor
nagios
Opis źródłowy (NVD)

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)1.8%
Opublikowano (NVD)2025-10-30 22:15:45 UTC
Ostatnia modyfikacja (NVD)2026-09-30 18:17:55 UTC
Referencje