PT-2014-2009 · Nagios+2 · Nagios Remote Plugin Executor+2

Published

2014-05-07

·

Updated

2024-08-06

·

CVE-2014-2913

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Nagios Remote Plugin Executor (NRPE) versions 2.15 and earlier
Description The issue is related to an incomplete blacklist vulnerability in the Nagios Remote Plugin Executor (NRPE), which allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check nrpe. This issue can only occur when the administrator enables the "dont blame nrpe" option in nrpe.conf, despite the "HIGH security risk" warning within the comments. It has been reported that the vendor allows newlines as "expected behavior." The issue is disputed by multiple parties.
Recommendations For Nagios Remote Plugin Executor (NRPE) versions 2.15 and earlier, consider disabling the "dont blame nrpe" option in nrpe.conf to minimize the risk of exploitation. As a temporary workaround, restrict access to the libexec/check nrpe endpoint to prevent remote attackers from executing arbitrary commands. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2143
ALT-PU-2020-1079
ALT-PU-2020-1106
BDU:2019-01845
CVE-2014-2913
MGASA-2014-0217
OPENSUSE-SU-2024:11099-1
SUSE-SU-2014_0682-1
SUSE-SU-2024:1417-1
SUSE-SU-2024_1417-1

Affected Products

Alt Linux
Nagios Remote Plugin Executor
Suse