Insecure Timing Comparison Vulnerability in Nagios XI
CVE-2023-24035
3.5LOW
What is CVE-2023-24035?
An insecure timing comparison vulnerability was identified in Nagios XI, which affects versions prior to 5.9.3. The flaw resides in the is_insecure_login_authenticated function and allows attackers to perform brute-force password attacks by analyzing timing differences during password comparison. This could potentially lead to unauthorized access to the admin panel, compromising the security of the system. Organizations using affected versions should prioritize upgrading to mitigate this risk.
Affected Version(s)
Nagios XI 0 < 5.9.3
