CVE-2025-28059: High severity nagios network analyzer vulnerability
An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke associated API tokens, enabling unauthorized access to restricted functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28059?
The severity of CVE-2025-28059 is currently classified as moderate due to potential unauthorized access to system resources.
How do I fix CVE-2025-28059?
To fix CVE-2025-28059, ensure that session invalidation and token revocation are properly implemented in the Nagios Network Analyzer configuration.
What versions of Nagios Network Analyzer are affected by CVE-2025-28059?
CVE-2025-28059 affects Nagios Network Analyzer version 2024R1.0.3.
What types of issues does CVE-2025-28059 cause?
CVE-2025-28059 allows deleted users to retain access to system resources, which poses a significant security risk.
Who should be concerned about CVE-2025-28059?
Administrators and security professionals using Nagios Network Analyzer should be concerned about CVE-2025-28059 due to the risk of unauthorized access.