Insecure Timing Comparison Vulnerability in Nagios XI
CVE-2023-24035

3.5LOW

Key Information:

Vendor

NagiOS

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2023-24035?

An insecure timing comparison vulnerability was identified in Nagios XI, which affects versions prior to 5.9.3. The flaw resides in the is_insecure_login_authenticated function and allows attackers to perform brute-force password attacks by analyzing timing differences during password comparison. This could potentially lead to unauthorized access to the admin panel, compromising the security of the system. Organizations using affected versions should prioritize upgrading to mitigate this risk.

Affected Version(s)

Nagios XI 0 < 5.9.3

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.