CVE-2025-34323

🟡 Monitoruj

Błąd konfiguracji sudo w Nagios Log Server umożliwia lokalną eskalację uprawnień do roota.

CVSS
7.8
EPSS
0.3%
Exploit
none
Vendor
nagios
Opis źródłowy (NVD)

Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The 'www-data' user is a member of the 'nagios' group, which has write access to '/usr/local/nagioslogserver/scripts', while several scripts in this directory are owned by root and may be executed via sudo without a password. A local attacker running as 'www-data' can move one of these root-owned scripts to a backup name and create a replacement script with attacker-controlled content at the original path, then invoke it with sudo. This allows arbitrary commands to be executed with root privileges, providing full compromise of the underlying operating system.

privilege-escalation Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-11-17 18:15:56 UTC
Ostatnia modyfikacja (NVD)2026-10-07 21:10:00 UTC
Referencje