Nagios Network Analyzer Broken Access Control Vulnerability Allowing Privilege Escalation

Vulnerability

A broken access control vulnerability has been identified in Nagios Network Analyzer version 2024R1.0.3. This vulnerability allows low-privilege users with 'Read-Only' access to execute administrative actions, such as stopping system services and deleting critical resources. The issue stems from inadequate authorization enforcement, which enables unauthorized modifications that could disrupt system integrity and availability.

Impact

Exploitation of this vulnerability could lead to unauthorized system service interruptions or critical resource deletions, causing operational disruptions and potential reputational damage.

Remediation

Users can update to Nagios Network Analyzer version 2024R2.0.1, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.