9.8
CVE-2025-34271
- EPSS 0.63%
- Veröffentlicht 30.10.2025 21:22:51
- Zuletzt bearbeitet 06.11.2025 16:29:46
- Quelle disclosure@vulncheck.com
- CVE-Watchlists
- Unerledigt
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept credentials in transit. Captured credentials could allow the attacker to authenticate as a cluster node or service account, enabling further unauthorized access, lateral movement, or system compromise.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nagios ≫ Log Server Version < 2024
Nagios ≫ Log Server Version2024 Updater1
Nagios ≫ Log Server Version2024 Updater1.0.1
Nagios ≫ Log Server Version2024 Updater1.0.2
Nagios ≫ Log Server Version2024 Updater1.1
Nagios ≫ Log Server Version2024 Updater1.2
Nagios ≫ Log Server Version2024 Updater1.3
Nagios ≫ Log Server Version2024 Updater1.3.1
Nagios ≫ Log Server Version2024 Updater1.3.2
Nagios ≫ Log Server Version2024 Updater1.3.3
Nagios ≫ Log Server Version2024 Updater1.3.4
Nagios ≫ Log Server Version2024 Updater1.3.5
Nagios ≫ Log Server Version2024 Updater2
Nagios ≫ Log Server Version2024 Updater2.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.63% | 0.697 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.