CRITICAL🇵🇱 Wersja polska

CVE-2025-34274

CVSS 9.3v4.0pub. 2025-10-30upd. 2025-11-06

Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. If an attacker is able to compromise the Logstash process - for example by exploiting an insecure plugin, pipeline configuration injection, or a vulnerability in input parsing - the attacker could execute code with root privileges, resulting in full system compromise. The Logstash service has been altered to run as the lower-privileged 'nagios' user to reduce this risk associated with a network-facing service that can accept untrusted input or load third-party components.

🤖 AI Analysis
How it works

The built-in Logstash process, which is a network service accepting potentially untrusted input, runs with the highest system privileges (root). An attacker can compromise it through various methods: by exploiting vulnerabilities in unsafe plugins, injecting pipeline configuration, or exploiting vulnerabilities in input data parsing mechanisms. Since Logstash accepts data from the network and can load external vendor components, the attack surface is extensive. After successful compromise of the Logstash process, any executed code automatically runs with root privileges.

Impact

An attacker who gains control over the Logstash process can execute arbitrary code with root privileges, leading to complete compromise of the operating system — including reading and modifying all data, installing backdoors, and lateral movement within the network.

Mitigation & patch

Update Nagios Log Server to version 2024R2.0.3 or later. In this version, the Logstash service has been changed to run under the unprivileged 'nagios' user account instead of root. Details of the fix are available in the vendor's official changelog and on the Nagios security page.

Who is affected

Nagios Log Server in versions earlier than 2024R2.0.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Nagios Log Server

    APP
    Nagios
    2024< 2024
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-34277CRITICAL9.4PL ✓same product

RCE w Nagios Log Server — code injection przez malformed dashboard ID

CVE-2025-44823CRITICAL9.9PL ✓same product

Nagios Log Server: ujawnienie kluczy API w postaci jawnej przez authenticated użytkownika

CVE-2025-34323HIGH8.5same product

Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combinati...

CVE-2025-34322HIGH8.6same product

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the...

CVE-2023-7322HIGH8.7same product

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked ...