← All CVEs

CVE-2013-1362

high · 7.5

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

7.5
CVSS
65.7%
EPSS (exploit prob.)
99th
EPSS percentile
2013-07-09
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
opensuseopensuse11.4
opensuseopensuse12.1
opensuseopensuse12.2
nagiosremote_plug_in_executor<= 2.13
nagiosremote_plug_in_executor1.3
nagiosremote_plug_in_executor1.4
nagiosremote_plug_in_executor1.5
nagiosremote_plug_in_executor1.6
nagiosremote_plug_in_executor1.7
nagiosremote_plug_in_executor1.8
nagiosremote_plug_in_executor1.9
nagiosremote_plug_in_executor2.0
nagiosremote_plug_in_executor2.0b1
nagiosremote_plug_in_executor2.0b2
nagiosremote_plug_in_executor2.0b3
nagiosremote_plug_in_executor2.0b4
nagiosremote_plug_in_executor2.0b5
nagiosremote_plug_in_executor2.3
nagiosremote_plug_in_executor2.4
nagiosremote_plug_in_executor2.5
nagiosremote_plug_in_executor2.5.1
nagiosremote_plug_in_executor2.5.2
nagiosremote_plug_in_executor2.6
nagiosremote_plug_in_executor2.7
nagiosremote_plug_in_executor2.7.1
nagiosremote_plug_in_executor2.8
nagiosremote_plug_in_executor2.8.1
nagiosremote_plug_in_executor2.8b1
nagiosremote_plug_in_executor2.9
nagiosremote_plug_in_executor2.10
nagiosremote_plug_in_executor2.11
nagiosremote_plug_in_executor2.12

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-1362