CVE-2023-24035

An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 04:16

Updated : 2026-09-14 04:16


NVD link : CVE-2023-24035

Mitre link : CVE-2023-24035

CVE.ORG link : CVE-2023-24035


JSON object : View

Products Affected

No product.

CWE
CWE-208

Observable Timing Discrepancy