CVE-2025-34298: fallo de gravedad alta en Nagios Log Server
Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.7epss 0.7%
probabilidad de explotación
0.7%top 48% de las CVE
explotación observada
noninguna fuente lo reporta
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Nagios · Log ServerCVEs relacionadas — Nagios Log Server
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-44823CRITICALCVE-2025-44823EPSS 16.1%CVE-2025-34322HIGHNagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language QueriesEPSS 9.5%CVE-2025-44824HIGHCVE-2025-44824EPSS 2.8%CVE-2025-34277CRITICALNagios Log Server < 2024R1.3.1 RCE via Malformed Dashboard IDEPSS 2.2%CVE-2025-34274CRITICALNagios Log Server < 2024R2.0.3 Logstash Process Root PrivilegesEPSS 2.1%CVE-2023-7322HIGHNagios Log Server < 2024R1 Incorrect Authorization Granting Full API AccessEPSS 1.1%