Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in the context of the web application service, resulting in remote code execution with the service's privileges.
History

Thu, 06 Nov 2025 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nagios:network_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:network_analyzer:2024:r1.0.1:*:*:*:*:*:*
cpe:2.3:a:nagios:network_analyzer:2024:r1.0.2:*:*:*:*:*:*
cpe:2.3:a:nagios:network_analyzer:2024:r1.0.3:*:*:*:*:*:*
cpe:2.3:a:nagios:network_analyzer:2024:r2:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Fri, 31 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios network Analyzer
Vendors & Products Nagios
Nagios network Analyzer

Thu, 30 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in the context of the web application service, resulting in remote code execution with the service's privileges.
Title Nagios Network Analyzer < 2024R2.0.1 RCE in LDAP Certificate Removal Function
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-10-30T21:27:41.203Z

Updated: 2025-10-31T15:10:43.481Z

Reserved: 2025-04-15T19:15:22.581Z

Link: CVE-2025-34280

cve-icon Vulnrichment

Updated: 2025-10-31T15:10:40.378Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-30T22:15:48.497

Modified: 2025-11-06T18:15:09.103

Link: CVE-2025-34280

cve-icon Redhat

No data.