CVE-2025-34280High· 7.2▾ TwilightNagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administra…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.4%
Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in the context of the web application service, resulting in remote code execution with the service's privileges.
network_analyzer < 2024network_analyzer = 2024Upgrade past the affected range:
network_analyzer 2024Connected by shared product, vendor, weakness, or advisory.
CVE-2025-34278Medium· 5.4Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the applicat…
CVE-2025-34322High· 7.2Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature
CVE-2025-34286High· 7.2Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command
CVE-2024-14003Critical· 9.8Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins
CVE-2024-14005High· 8.8Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard
CVE-2024-14008High· 7.2Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard