PT-2025-44520 · Nagios · Nagios Network Analyzer

Haoyu Li

+5

·

Published

2025-10-30

·

Updated

2025-10-31

·

CVE-2025-34280

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios Network Analyzer versions prior to 2024R2.0.1
Description Nagios Network Analyzer contains a flaw in how it handles LDAP certificate management. Specifically, the certificate removal process does not properly sanitize input. An authenticated administrator can exploit this to execute commands on the host system, with the privileges of the web application service, leading to remote code execution.
Recommendations Update to version 2024R2.0.1 or later.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-15974
CVE-2025-34280

Affected Products

Nagios Network Analyzer