CVE-2020-6581: Command Injection
Published Mar 16, 2020
·Updated
Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nastymetachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection.
Affected Software
2 affected components
Nagios Remote Plug In Executor=3.2.1
Fedoraproject Fedora=32
Event History
Mar 16, 2020
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-6581?
CVE-2020-6581 is considered a high severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2020-6581?
To fix CVE-2020-6581, upgrade Nagios NRPE to version 3.2.2 or later.
3
What software is affected by CVE-2020-6581?
CVE-2020-6581 affects Nagios Remote Plugin Executor version 3.2.1 and Fedora 32.
4
What type of vulnerability is CVE-2020-6581?
CVE-2020-6581 is classified as a command injection vulnerability due to insufficient filtering.
5
Can CVE-2020-6581 lead to further exploits?
Yes, CVE-2020-6581 can lead to further exploits by giving attackers the ability to execute arbitrary commands.