PT-2025-44520 · Nagios · Nagios Network Analyzer
Haoyu Li
+5
·
Published
2025-10-30
·
Updated
2025-10-31
·
CVE-2025-34280
CVSS v2.0
9.0
High
| AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Nagios Network Analyzer versions prior to 2024R2.0.1
Description
Nagios Network Analyzer contains a flaw in how it handles LDAP certificate management. Specifically, the certificate removal process does not properly sanitize input. An authenticated administrator can exploit this to execute commands on the host system, with the privileges of the web application service, leading to remote code execution.
Recommendations
Update to version 2024R2.0.1 or later.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Network Analyzer