---
id: CVE-2025-34280
title: "Nagios\_Network Analyzer versions prior to\_2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation"
summary: "Nagios\_Network Analyzer versions prior to\_2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administra…"
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: nagios
product: network_analyzer
affected:
  - network_analyzer < 2024
  - network_analyzer = 2024
patched:
  - network_analyzer 2024
published: '2025-10-30'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34280'
references:
  - url: 'https://www.nagios.com/changelog/nagios-network-analyzer/'
    label: disclosure@vulncheck.com
  - url: 'https://www.nagios.com/products/security/#network-analyzer'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nagios-network-analyzer-rce-in-ldap-certificate-removal-function
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.01428
epssPercentile: 0.72167
ingestedAt: '2026-10-07T21:54:14.906Z'
---

## Overview

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in the context of the web application service, resulting in remote code execution with the service's privileges.

## Affected

- `network_analyzer < 2024`
- `network_analyzer = 2024`

## Remediation

Upgrade past the affected range:

- `network_analyzer 2024`
