📦

remote_plug_in_executor

Vendor: nagios

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 7 Total Indexed
Avg. EPSS 23.74% Exploit Prob.
Latest CVE CVE-2020-6582 Mar 16

Security Vulnerability Index

Page 1 / 1
7.5 CVSS

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

EPSS: 3.87%
7.3 CVSS

Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection.

EPSS: 1.61%
7.5 CVSS
CVE-2013-1362
Exploit Found

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

EPSS: 65.72%