PT-2023-5555 · Unknown+3 · Nagios Plugins+3
Megamansec
·
Published
2023-08-23
·
Updated
2024-10-15
·
CVE-2023-37154
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Nagios nagios-plugins version 2.4.5
Description
The issue concerns arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with
${IFS} in the check by ssh component of Nagios nagios-plugins. This allows a remote attacker to execute arbitrary commands. The vulnerability is related to the lack of measures to neutralize special elements used in operating system commands.Recommendations
For Nagios nagios-plugins version 2.4.5, update to the latest version to mitigate the risk of arbitrary command execution. As a temporary workaround, consider disabling the
check by ssh function until a patch is available. Restrict access to the ProxyCommand, LocalCommand, and PermitLocalCommand configurations to minimize the risk of exploitation. Avoid using the ${IFS} variable in the affected SSH configurations until the issue is resolved.Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Nagios
Red Os
Nagios Plugins