Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept credentials in transit. Captured credentials could allow the attacker to authenticate as a cluster node or service account, enabling further unauthorized access, lateral movement, or system compromise.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "There was an issue in Nagios Log Server where requests for credentials from a cluster manager would not use SSL, even if SSL was enabled" and "Fixed issue with requesting credentials from a cluster manager wouldn’t use SSL if enabled."


Workaround

No workaround given by the vendor.

History

Mon, 17 Nov 2025 21:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nagios:log_server:2024:*:*:*:*:*:*:*

Thu, 06 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1.0.1:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1.0.2:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1.1:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1.2:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1.3.1:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1.3.2:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1.3.3:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1.3.4:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1.3.5:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1.3:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r1:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r2.0.1:*:*:*:*:*:*
cpe:2.3:a:nagios:log_server:2024:r2:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 31 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios log Server
Vendors & Products Nagios
Nagios log Server

Thu, 30 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept credentials in transit. Captured credentials could allow the attacker to authenticate as a cluster node or service account, enabling further unauthorized access, lateral movement, or system compromise.
Title Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext
Weaknesses CWE-319
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-17T21:36:24.505Z

Reserved: 2025-04-15T19:15:22.580Z

Link: CVE-2025-34271

cve-icon Vulnrichment

Updated: 2025-10-31T15:14:26.854Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-30T22:15:47.673

Modified: 2025-11-06T16:29:46.200

Link: CVE-2025-34271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-31T10:13:56Z