Junglewise Threat Intelligence

CVE-2023-24035: Nagios XI insecure timing comparison in authentication

CVE-2023-24035 · Severity: low · CVSS 3.5 · Published 2026-09-14

Technologies: Nagios XI. Vendors: Nagios.

Executive brief

Nagios XI is an enterprise monitoring platform used to track infrastructure health and performance. A timing-based password brute force vulnerability in the authentication function allows attackers to guess the admin password by analyzing slight differences in response times, potentially leading to complete compromise of the monitoring system and exposure of monitored infrastructure.

Technical details

The vulnerability exists in the is_insecure_login_authenticated function, which uses insecure timing comparison to validate credentials. This timing attack allows an attacker to bruteforce the admin password by measuring response time differences—correct password characters take slightly longer to compare than incorrect ones, leaking information character-by-character. The attack is network-reachable and requires no prior authentication. Patches are available in Nagios XI 5.9.3 and later.

Affected products

  • Nagios XI before 5.9.3

Timeline

  • 2026-09-14: disclosed

References

Related threats