---
id: CVE-2025-34270
title: >-
  Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the
  AD/LDAP user import functionality as it fails to obfuscate the password field
  during import
summary: >-
  Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the
  AD/LDAP user import functionality as it fails to obfuscate the password field
  during import. As a result, the plaintext password supplied for imported
  accounts…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-312
  - CWE-522
vendor: nagios
product: log_server
affected:
  - log_server < 2024
  - log_server = 2024
patched:
  - log_server 2024
published: '2025-10-30'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34270'
references:
  - url: >-
      https://support.nagios.com/kb/article/authenticating-and-importing-users-with-ad-and-ldap-995.html
    label: disclosure@vulncheck.com
  - url: 'https://www.nagios.com/changelog/#log-server'
    label: disclosure@vulncheck.com
  - url: 'https://www.nagios.com/products/security/#log-server-2024R2'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nagios-log-server-ad-ldap-import-password-not-obfuscated
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00626
epssPercentile: 0.48383
ingestedAt: '2026-10-07T21:54:14.903Z'
---

## Overview

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnostic output. This can leak sensitive credentials to administrators or anyone with access to import results.

## Affected

- `log_server < 2024`
- `log_server = 2024`

## Remediation

Upgrade past the affected range:

- `log_server 2024`
