CVE-2023-37154

HIGH

Nagios nagios-plugins <2.4.5 - Command Injection

Title source: llm
STIX 2.1

Description

check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.

Scores

CVSS v3 8.4
EPSS 0.0046
EPSS Percentile 36.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Published Oct 09, 2024
Tracked Since Feb 18, 2026