PT-2025-27669 · Unknown · Nos Client
Bzyo
+2
·
Published
2025-07-02
·
Updated
2025-09-17
·
CVE-2025-34078
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
NSClient++ version 0.5.2.35
Description:
A local privilege escalation issue exists when both the web interface and ExternalScripts features are enabled. The configuration file (nsclient.ini) stores the administrative password in plaintext and is readable by local users. An attacker can extract this password, authenticate to the NSClient++ web interface (typically accessible on port 8443), and abuse the ExternalScripts plugin to inject and execute arbitrary commands as SYSTEM. This can be done by registering a custom script, saving the configuration, and triggering it via the API.
Recommendations:
For NSClient++ version 0.5.2.35, consider disabling the ExternalScripts feature and restricting access to the web interface until a secure configuration or update is available. As a temporary workaround, restrict access to the nsclient.ini configuration file to prevent local users from reading the administrative password.
Exploit
Fix
LPE
Improper Privilege Management
Insufficiently Protected Credentials
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nos Client