CVE-2023-47406 is an information disclosure issue in Nagios XI affecting the Scheduled Backups FTP connectivity test functionality. According to the provided context, the feature exhibits a discrepancy in error-message timing depending on whether a target port is open or closed. An attacker can abuse these timing differences to infer port state and perform time-based port scanning against the Nagios XI server itself, including localhost, and potentially internal network hosts reachable from the server. The issue was reported in Nagios XI v5.11.1 and was mitigated in version 5.11.4.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information disclosure issue in Nagios XI's scheduled backup connectivity test that can be abused for time-based port scanning of localhost or internal network hosts.
A low-severity information disclosure issue in Nagios XI's scheduled backups feature that allows administrators to infer whether ports are open or closed on localhost or internal hosts based on response timing differences.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.