CVE-2025-34298 is a high-severity privilege escalation vulnerability affecting Nagios Log Server versions prior to 2024R1.3.2. An authenticated user can manipulate their account's email address to an invalid value, exploiting insufficient validation and authorization checks to gain elevated privileges or bypass access controls. With a CVSS score of 8.8, this vulnerability presents a significant risk for full confidentiality, integrity, and availability compromise. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2024CPE matchmatch criteria | cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*:* | ||
2024CPE matchmatch criteria | cpe:2.3:a:nagios:log_server:2024:r1:*:*:*:*:*:* | ||
2024CPE matchmatch criteria | cpe:2.3:a:nagios:log_server:2024:r1.0.1:*:*:*:*:*:* | ||
2024CPE matchmatch criteria | cpe:2.3:a:nagios:log_server:2024:r1.0.2:*:*:*:*:*:* | ||
2024CPE matchmatch criteria | cpe:2.3:a:nagios:log_server:2024:r1.1:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.