CVE 8.5 HIGH

Nagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules_CVE-2025-34323

8.5 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to unsafe interaction between sudo rules and file system permissions. The web server account is granted passwordless sudo access to certain maintenance scripts while also being a member of a group that has write access to the directory containing those scripts. A local attacker running as the web server user can replace one of the permitted scripts with a malicious program and then execute it via sudo, resulting in arbitrary code execution with root privileges.

AI Analysis

Local privilege escalation vulnerability in Nagios Log Server due to unsafe interaction between sudo rules and file system permissions, allowing arbitrary code execution with root privileges.

Basic Information

ID CVE-2025-34323
Source VulnCheck
Published Nov 17, 2025 at 17:48
Modified Nov 17, 2025 at 21:36

Affected Product

Vendor Nagios
Product Log Server
Affected Versions Nagios Log Server 0

CWE Classification

AI Assessment

AI Score 8.5 / 10
AI Severity High
Vendor Nagios
Product Nagios Log Server
Version < 2026R1.0.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.