CVE-2025-28131

A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:nagios:network_analyzer:2024:r1.0.3:*:*:*:*:*:*

History

11 Jul 2025, 13:39

Type Values Removed Values Added
CPE cpe:2.3:a:nagios:nagios_network_analyzer:2024:r1.0.3:*:*:*:*:*:* cpe:2.3:a:nagios:network_analyzer:2024:r1.0.3:*:*:*:*:*:*
First Time Nagios network Analyzer

20 Jun 2025, 15:29

Type Values Removed Values Added
References () https://github.com/harshal79/Privilege-Escalation-in-Nagios-Network-Analyzer.git - () https://github.com/harshal79/Privilege-Escalation-in-Nagios-Network-Analyzer.git - Third Party Advisory
References () https://www.nagios.com/changelog/#network-analyzer - () https://www.nagios.com/changelog/#network-analyzer - Release Notes
CPE cpe:2.3:a:nagios:nagios_network_analyzer:2024:r1.0.3:*:*:*:*:*:*
First Time Nagios
Nagios nagios Network Analyzer

01 Apr 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-01 17:15

Updated : 2025-07-11 13:39


NVD link : CVE-2025-28131

Mitre link : CVE-2025-28131


JSON object : View

Products Affected

nagios

  • network_analyzer
CWE

No CWE.