Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3wc8-676p-crj6

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 9.8

Описание

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept credentials in transit. Captured credentials could allow the attacker to authenticate as a cluster node or service account, enabling further unauthorized access, lateral movement, or system compromise.

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept credentials in transit. Captured credentials could allow the attacker to authenticate as a cluster node or service account, enabling further unauthorized access, lateral movement, or system compromise.

EPSS

Процентиль: 71%
0.00661
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network path can intercept credentials in transit. Captured credentials could allow the attacker to authenticate as a cluster node or service account, enabling further unauthorized access, lateral movement, or system compromise.

CVSS3: 7.5
fstec
7 месяцев назад

Уязвимость компонента управления кластером cluster manager программного средства мониторинга и анализа логов Nagios Log Server, позволяющая нарушителю перехватить учётные данные пользователя

EPSS

Процентиль: 71%
0.00661
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-319