CNNVD-202510-4087 Information

CNNVD ID

CNNVD-202510-4087

CVE-2025-34271

  • CNNVD Published: 2025-10-30

Description (Chinese)

Nagios Log Server是美国Nagios公司的一套集中式日志管理、监控和分析软件。 Nagios Log Server 2024R2.0.2之前版本存在安全漏洞,该漏洞源于集群管理器组件在未加密通道上请求敏感凭据,可能导致凭据被拦截和未经授权的访问。

Description (English)

Nagios Log Server is a centralized log management, monitoring and analysis software for the United States company Nagios. There was a security loophole in the pre-Nagios Log Server 2024R2.0.2 version, which stemmed from the fact that cluster manager components requested sensitive evidence on unencrypted routes, which could lead to interception and unauthorized access.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Nagios

Published

2025-10-30

Last Modified

2026-02-24

References

https://www.nagios.com/changelog/#log-server https://www.nagios.com/products/security/#log-server-2024R2 https://www.vulncheck.com/advisories/nagios-log-server-cluster-manager-credential-requests-sent-over-plaintext

Patch

https://www.nagios.com/products/security/#log-server-2024R2

Share on: