VYPR
Medium severity4.6NVD Advisory· Published Apr 1, 2025· Updated Jun 17, 2026

CVE-2025-28131

CVE-2025-28131

Description

A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Nagios/Network Analyzerllm-fuzzy3 versions
    2024R1.0.3+ 2 more
    • (no CPE)range: 2024R1.0.3
    • (no CPE)
    • cpe:2.3:a:nagios:network_analyzer:2024:r1.0.3:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.