PT-2025-41174 · Nagios · Nagios Log Server

Published

2025-04-08

·

Updated

2025-12-11

·

CVE-2025-44823

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nagios Log Server versions prior to 2024R1.3.2
Description Nagios Log Server before version 2024R1.3.2 has a flaw that allows authenticated users to retrieve cleartext administrative API keys. This is achieved by sending a specially crafted GET request to the /nagioslogserver/index.php/api/system/get users API Endpoint. The retrieved keys could allow an attacker to gain full system compromise. The vulnerability is identified as GL:NLS#475.
Recommendations Upgrade to Nagios Log Server version 2024R1.3.2 or later.

Exploit

Fix

Information Disclosure

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-14348
CVE-2025-44823

Affected Products

Nagios Log Server