PT-2025-41174 · Nagios · Nagios Log Server
Published
2025-04-08
·
Updated
2025-12-11
·
CVE-2025-44823
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nagios Log Server versions prior to 2024R1.3.2
Description
Nagios Log Server before version 2024R1.3.2 has a flaw that allows authenticated users to retrieve cleartext administrative API keys. This is achieved by sending a specially crafted GET request to the
/nagioslogserver/index.php/api/system/get users API Endpoint. The retrieved keys could allow an attacker to gain full system compromise. The vulnerability is identified as GL:NLS#475.Recommendations
Upgrade to Nagios Log Server version 2024R1.3.2 or later.
Exploit
Fix
Information Disclosure
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nagios Log Server