由于没有看到实际的网页截图,我将基于提供的信息来总结关键的漏洞信息。以下是关于Nagios XI漏洞的关键信息,以简洁的Markdown格式呈现: 关键漏洞信息 漏洞名称: - Nagios XI < 2024R1.1.2 API Keys & Hashed Passwords Authenticated Information Disclosure 严重性: - HIGH 日期: - October 30, 2025 影响版本: - XI < 2024R1.1.2 CVE ID: - CVE-2024-13995 CWE类型: - CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere CVSS评分: - 7.1 CVSS V4向量: - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N 参考资料: - Nagios XI Security Disclosures - Nagios XI Changelog 描述: - Nagios XI versions prior to 2024R1.1.2 may disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts. 若有实际截图中的其他重要信息,欢迎继续补充!