CVE-2023-24035: Nagios XI

Low severity, CVSS 3.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison.

Affected products

  • Nagios Nagios XI: before 5.9.3 (fixed in 5.9.3)

Published 2026-09-14. Last modified 2026-09-22.