{"id":"CVE-2024-13999","title":"Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user","summary":"Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authen…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-497"],"vendor":"nagios","product":"nagios_xi","affected":["nagios_xi < 2024","nagios_xi = 2024"],"patched":["nagios_xi 2024"],"published":"2025-10-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T18:17:55.190","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-13999","references":[{"url":"https://www.nagios.com/changelog/nagios-xi/","label":"disclosure@vulncheck.com"},{"url":"https://www.nagios.com/products/security/#nagios-xi","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/nagios-xi-ad-ldap-token-authenticated-information-disclosure","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","score-dispute"],"epss":0.01883,"epssPercentile":0.78719,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2025-10-31T15:07:51.139533Z"},"scores":{"nvd":9.8,"cna":7.3},"ingestedAt":"2026-09-30T18:17:24.565Z","slug":"CVE-2024-13999","body":"## Overview\n\nNagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.\n\n## Affected\n\n- `nagios_xi < 2024`\n- `nagios_xi = 2024`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `nagios_xi 2024`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[{"seq":213868,"id":"CVE-2024-13999","ts":1790796114428,"field":"cvss","old":"7.3","new":"9.8"},{"seq":213867,"id":"CVE-2024-13999","ts":1790796114428,"field":"severity","old":"high","new":"critical"}]}