Unrated severityNVD Advisory· Published Oct 30, 2025· Updated Nov 17, 2025
Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext
CVE-2025-34271
Description
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept credentials in transit. Captured credentials could allow the attacker to authenticate as a cluster node or service account, enabling further unauthorized access, lateral movement, or system compromise.
Affected products
2- Range: <2024R2.0.2
- Nagios/Log Serverv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.nagios.com/changelog/mitrerelease-notespatch
- www.nagios.com/products/security/mitrevendor-advisorypatch
- www.vulncheck.com/advisories/nagios-log-server-cluster-manager-credential-requests-sent-over-plaintextmitrethird-party-advisory
News mentions
0No linked articles in our index yet.