Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web user (or the backend shell user) to escalate to root on the host.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios
Nagios log Server |
|
| Vendors & Products |
Nagios
Nagios log Server |
Thu, 30 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web user (or the backend shell user) to escalate to root on the host. | |
| Title | Nagios Log Server < 2024R1.0.2 LPE from Apache/Backend Shell User to Root | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-10-30T21:24:15.621Z
Updated: 2025-10-31T17:23:05.220Z
Reserved: 2025-10-20T19:35:53.948Z
Link: CVE-2024-58273
Updated: 2025-10-31T17:22:59.755Z
Status : Received
Published: 2025-10-30T22:15:46.737
Modified: 2025-10-30T22:15:46.737
Link: CVE-2024-58273
No data.