CVE-2025-44823: Critical severity Nagios Log Server vulnerability
Published Oct 7, 2025
·Updated
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/getusers call. This is GL:NLS#475.
Affected Software
9 affected components
Nagios Log Server<2024R1.3.2
Nagios Log Server<2024
Nagios Log Server=2024-r1
Nagios Log Server=2024-r1.0.1
Nagios Log Server=2024-r1.0.2
Nagios Log Server=2024-r1.1
Nagios Log Server=2024-r1.2
Nagios Log Server=2024-r1.3
Nagios Log Server=2024-r1.3.1
Event History
Oct 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44823?
CVE-2025-44823 is classified with a medium severity level due to its potential for exposing sensitive administrative API keys.
2
How does CVE-2025-44823 affect Nagios Log Server?
CVE-2025-44823 allows authenticated users to access cleartext administrative API keys through an unprotected API call.
3
How do I fix CVE-2025-44823?
To fix CVE-2025-44823, upgrade Nagios Log Server to version 2024R1.3.2 or later.
4
Who is affected by CVE-2025-44823?
Organizations using Nagios Log Server versions prior to 2024R1.3.2 are vulnerable to CVE-2025-44823.
5
What are the implications of CVE-2025-44823?
The implications of CVE-2025-44823 include potential unauthorized access to sensitive credentials, which can lead to further exploitation.