CVE-2025-34271: Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept credentials in transit. Captured credentials could allow the attacker to authenticate as a cluster node or service account, enabling further unauthorized access, lateral movement, or system compromise.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34271?
CVE-2025-34271 is considered a critical vulnerability due to the exposure of sensitive credentials over an unencrypted channel.
How do I fix CVE-2025-34271?
To fix CVE-2025-34271, upgrade Nagios Log Server to version 2024R2.0.2 or later.
What component of Nagios Log Server is affected by CVE-2025-34271?
CVE-2025-34271 affects the cluster manager component of Nagios Log Server.
What versions of Nagios Log Server are vulnerable to CVE-2025-34271?
Nagios Log Server versions prior to 2024R2.0.2 are vulnerable to CVE-2025-34271.
What type of attacks can exploit CVE-2025-34271?
Attackers can exploit CVE-2025-34271 to intercept sensitive credentials transmitted over an insecure channel.