9.8

CVE-2025-34271

Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept credentials in transit. Captured credentials could allow the attacker to authenticate as a cluster node or service account, enabling further unauthorized access, lateral movement, or system compromise.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nagios ≫ Log Server Version < 2024
Nagios ≫ Log Server Version 2024 Update r1
Nagios ≫ Log Server Version 2024 Update r1.0.1
Nagios ≫ Log Server Version 2024 Update r1.0.2
Nagios ≫ Log Server Version 2024 Update r1.1
Nagios ≫ Log Server Version 2024 Update r1.2
Nagios ≫ Log Server Version 2024 Update r1.3
Nagios ≫ Log Server Version 2024 Update r1.3.1
Nagios ≫ Log Server Version 2024 Update r1.3.2
Nagios ≫ Log Server Version 2024 Update r1.3.3
Nagios ≫ Log Server Version 2024 Update r1.3.4
Nagios ≫ Log Server Version 2024 Update r1.3.5
Nagios ≫ Log Server Version 2024 Update r2
Nagios ≫ Log Server Version 2024 Update r2.0.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.492
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
disclosure@vulncheck.com 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

https://www.nagios.com/changelog/#log-server
Release Notes
https://www.vulncheck.com/advisories/nagios-log-server-cluster-manager-credential-requests-sent-over-plaintext
Third Party Advisory
https://www.nagios.com/products/security/#log-server-2024R2
Vendor Advisory