PT-2014-2009 · Nagios+2 · Nagios Remote Plugin Executor+2
Published
2014-05-07
·
Updated
2024-08-06
·
CVE-2014-2913
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Nagios Remote Plugin Executor (NRPE) versions 2.15 and earlier
Description
The issue is related to an incomplete blacklist vulnerability in the Nagios Remote Plugin Executor (NRPE), which allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check nrpe. This issue can only occur when the administrator enables the "dont blame nrpe" option in nrpe.conf, despite the "HIGH security risk" warning within the comments. It has been reported that the vendor allows newlines as "expected behavior." The issue is disputed by multiple parties.
Recommendations
For Nagios Remote Plugin Executor (NRPE) versions 2.15 and earlier, consider disabling the "dont blame nrpe" option in nrpe.conf to minimize the risk of exploitation. As a temporary workaround, restrict access to the libexec/check nrpe endpoint to prevent remote attackers from executing arbitrary commands. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Nagios Remote Plugin Executor
Suse