PT-2025-14371 · Nagios · Nagios Network Analyzer
Published
2025-04-01
·
Updated
2025-04-05
·
CVE-2025-28132
CVSS v3.1
4.6
Medium
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nagios Network Analyzer version 2024R1.0.3
Description
A session management flaw allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session tokens remain valid beyond logout, allowing an attacker to impersonate users and perform actions on their behalf.
Recommendations
For Nagios Network Analyzer version 2024R1.0.3, consider implementing a session expiration mechanism that invalidates session tokens upon user logout as a temporary workaround until a patch is available. Restrict access to sensitive features and monitor user activity to minimize the risk of exploitation.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Network Analyzer