CVE-2023-48082
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.
CRITICAL · CVSS 9.1
EPSS 0.01145
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0