← Back

CVE-2025-44824

nvd nist
Published: Oct 7, 2025Modified: Nov 6, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/index.php/api/system/stop?subsystem=elasticsearch call. The service stops even though "message": "Could not stop elasticsearch" is in the API response. This is GL:NLS#474.

Affected (8)

Products: Nagios: Log Server
1 product
Log Server
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Nagios
Before 2024
Version 2024 r1.0.1
Version 2024 r1.0.2
Version 2024 r1.1
Version 2024 r1.2
Version 2024 r1.3.1
Version 2024 r1.3
Version 2024 r1

References (3)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Release Notes
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.