关键漏洞信息 漏洞名称: Nagios XI < 2024R1.1.3 Session Not Invalidated After Password Change 严重程度: Critical 日期: October 30, 2025 影响版本: XI < 2024R1.1.3 CVE编号: CVE-2024-13996 CWE类型: CWE-613 Insufficient Session Expiration CVSS 评分: 9.2 CVSS V4 Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N 描述 Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access to user data and actions even after a password change. 参考链接: Nagios XI Security Disclosures Nagios XI Changelog 发现者: Jack Eli