Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in the context of the web application service, resulting in remote code execution with the service's privileges.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "Nagios Network Analyzer was vulnerable to remote code execution through the function used to remove an LDAP certificate" and "Fixed a security vulnerability while removing a AD/LDAP certificate."


Workaround

No workaround given by the vendor.

History

Thu, 30 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in the context of the web application service, resulting in remote code execution with the service's privileges.
Title Nagios Network Analyzer < 2024R2.0.1 RCE in LDAP Certificate Removal Function
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-30T21:27:41.203Z

Reserved: 2025-04-15T19:15:22.581Z

Link: CVE-2025-34280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-30T22:15:48.497

Modified: 2025-10-30T22:15:48.497

Link: CVE-2025-34280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.