CVE-2013-1362
Opensuse < 2.13 - Improper Input Validation
Title source: ruleDescription
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/24955
metasploit
WORKING POC
EXCELLENT
by Rudolph Pereir · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/misc/nagios_nrpe_arguments.rb
References (6)
Scores
EPSS
0.7644
EPSS Percentile
98.9%
Details
CWE
CWE-20
Status
published
Products (32)
nagios/remote_plug_in_executor
1.3
nagios/remote_plug_in_executor
1.4
nagios/remote_plug_in_executor
1.5
nagios/remote_plug_in_executor
1.6
nagios/remote_plug_in_executor
1.7
nagios/remote_plug_in_executor
1.8
nagios/remote_plug_in_executor
1.9
nagios/remote_plug_in_executor
2.0
nagios/remote_plug_in_executor
2.0b1
nagios/remote_plug_in_executor
2.0b2
... and 22 more
Published
Jul 09, 2013
Tracked Since
Feb 18, 2026