PT-2023-5555 · Nagios+3 · Nagios+3

·

CVE-2023-37154

·

Publicado

2023-08-23

·

Atualizado

2024-10-15

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios nagios-plugins version 2.4.5
Description The issue concerns arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with ${IFS} in the check by ssh component of Nagios nagios-plugins. This allows a remote attacker to execute arbitrary commands. The vulnerability is related to the lack of measures to neutralize special elements used in operating system commands.
Recommendations For Nagios nagios-plugins version 2.4.5, update to the latest version to mitigate the risk of arbitrary command execution. As a temporary workaround, consider disabling the check by ssh function until a patch is available. Restrict access to the ProxyCommand, LocalCommand, and PermitLocalCommand configurations to minimize the risk of exploitation. Avoid using the ${IFS} variable in the affected SSH configurations until the issue is resolved.

Exploit

Correção

DoS

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06206
CVE-2023-37154
GHSA-P3GV-VMPX-HHW4

Produtos afetados

Debian
Nagios
Red Os
Nagios Plugins