# CVE-2024-13996

## Summary

- **CVE ID:** CVE-2024-13996
- **Severity:** CRITICAL
- **CVSS Score:** 9.2 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-613
- **Published:** Oct 30, 2025
- **Last Modified:** Mar 13, 2026

## Description

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access to user data and actions even after a password change.

## Affected Products

- Nagios — XI (0)

## References

- [CNA](https://www.nagios.com/products/security/#nagios-xi)
- [CNA](https://www.nagios.com/changelog/nagios-xi/)
- [CNA](https://www.vulncheck.com/advisories/nagios-xi-session-not-invalidated-after-password-change)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.99%
- **EPSS Percentile:** 60.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._