CVE-2025-34270
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-30
Last updated on: 2025-11-06
Assigner: VulnCheck
Description
Description
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnostic output. This can leak sensitive credentials to administrators or anyone with access to import results.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nagios | log_server | to 2024 (exc) |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
| nagios | log_server | 2024 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-312 | The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. |
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |
Attack-Flow Graph
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70