CVE-2013-1362: Input Validation
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1362?
CVE-2013-1362 has been rated as a medium-severity vulnerability, primarily due to its potential to allow remote command execution.
How do I fix CVE-2013-1362?
To fix CVE-2013-1362, upgrade Nagios Remote Plug-In Executor (NRPE) to version 2.14 or higher.
What versions are affected by CVE-2013-1362?
CVE-2013-1362 affects versions of Nagios Remote Plug-In Executor prior to 2.14, including 1.3 through 2.12 as well as certain openSUSE versions.
What are the potential impacts of CVE-2013-1362?
Exploiting CVE-2013-1362 could allow an attacker to execute arbitrary shell commands on a targeted system.
Is CVE-2013-1362 easy to exploit?
Yes, CVE-2013-1362 can be exploited easily by an attacker with remote access, especially if proper input validation is not in place.