CVE-2013-1362

Opensuse < 2.13 - Improper Input Validation

Title source: rule

Description

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/24955
metasploit WORKING POC EXCELLENT
by Rudolph Pereir · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/misc/nagios_nrpe_arguments.rb

Scores

EPSS 0.7644
EPSS Percentile 98.9%

Details

CWE
CWE-20
Status published
Products (32)
nagios/remote_plug_in_executor 1.3
nagios/remote_plug_in_executor 1.4
nagios/remote_plug_in_executor 1.5
nagios/remote_plug_in_executor 1.6
nagios/remote_plug_in_executor 1.7
nagios/remote_plug_in_executor 1.8
nagios/remote_plug_in_executor 1.9
nagios/remote_plug_in_executor 2.0
nagios/remote_plug_in_executor 2.0b1
nagios/remote_plug_in_executor 2.0b2
... and 22 more
Published Jul 09, 2013
Tracked Since Feb 18, 2026