CVE-2025-28131

A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nagios:network_analyzer:2024:r1.0.3:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-01 17:15

Updated : 2025-07-11 13:39


NVD link : CVE-2025-28131

Mitre link : CVE-2025-28131

CVE.ORG link : CVE-2025-28131


JSON object : View

Products Affected

nagios

  • network_analyzer
CWE
CWE-285

Improper Authorization