CVE-2013-7107
Summary
| CVE | CVE-2013-7107 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-15 16:08:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS: 0.001280000 probability, percentile 0.317920000 (date 2026-05-01)
Problem Types: CWE-352 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Icinga | Icinga | 0.8.0 | All | All | All |
| Application | Icinga | Icinga | 0.8.1 | All | All | All |
| Application | Icinga | Icinga | 0.8.2 | All | All | All |
| Application | Icinga | Icinga | 0.8.3 | All | All | All |
| Application | Icinga | Icinga | 0.8.4 | All | All | All |
| Application | Icinga | Icinga | 1.0 | All | All | All |
| Application | Icinga | Icinga | 1.0 | rc1 | All | All |
| Application | Icinga | Icinga | 1.0.1 | All | All | All |
| Application | Icinga | Icinga | 1.0.2 | All | All | All |
| Application | Icinga | Icinga | 1.0.3 | All | All | All |
| Application | Icinga | Icinga | 1.10.0 | All | All | All |
| Application | Icinga | Icinga | 1.10.1 | All | All | All |
| Application | Icinga | Icinga | 1.2.0 | All | All | All |
| Application | Icinga | Icinga | 1.2.1 | All | All | All |
| Application | Icinga | Icinga | 1.3.0 | All | All | All |
| Application | Icinga | Icinga | 1.3.1 | All | All | All |
| Application | Icinga | Icinga | 1.4.0 | All | All | All |
| Application | Icinga | Icinga | 1.4.1 | All | All | All |
| Application | Icinga | Icinga | 1.6.0 | All | All | All |
| Application | Icinga | Icinga | 1.6.1 | All | All | All |
| Application | Icinga | Icinga | 1.6.2 | All | All | All |
| Application | Icinga | Icinga | 1.7.0 | All | All | All |
| Application | Icinga | Icinga | 1.7.1 | All | All | All |
| Application | Icinga | Icinga | 1.7.2 | All | All | All |
| Application | Icinga | Icinga | 1.7.3 | All | All | All |
| Application | Icinga | Icinga | 1.7.4 | All | All | All |
| Application | Icinga | Icinga | 1.8.0 | All | All | All |
| Application | Icinga | Icinga | 1.8.1 | All | All | All |
| Application | Icinga | Icinga | 1.8.2 | All | All | All |
| Application | Icinga | Icinga | 1.8.3 | All | All | All |
| Application | Icinga | Icinga | 1.8.4 | All | All | All |
| Application | Icinga | Icinga | 1.8.5 | All | All | All |
| Application | Icinga | Icinga | 1.9.0 | All | All | All |
| Application | Icinga | Icinga | 1.9.1 | All | All | All |
| Application | Icinga | Icinga | 1.9.2 | All | All | All |
| Application | Icinga | Icinga | 1.9.3 | All | All | All |
| Application | Icinga | Icinga | 1.9.4 | All | All | All |
| Application | Icinga | Icinga | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| openSUSE-SU-2014:0269-1: moderate: update for icinga | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Icinga Security Releases – 1.10.2, 1.9.4, 1.8.5 - - Icinga: Open Source Monitoring | af854a3a-2127-422b-91ae-364da2661108 | www.icinga.org | Vendor Advisory |
| Bug #5250: fix possible buffer overflows CVE-2013-7106 - Classic UI - Open Source Monitoring | af854a3a-2127-422b-91ae-364da2661108 | dev.icinga.org | Vendor Advisory |
| oss-security - Fwd: Vulnerability (Buffer Overflow) in Icinga 1.8, 1.9 and 1.10 (Icinga Issue #5250) Vulnerability (Off-by-one memory access) in Icinga 1.8, 1.9 and 1.10 (Icinga Issue #5251) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Bug #5346: fix vulnerability against CSRF attacks CVE-2013-7107 - Classic UI - Open Source Monitoring | af854a3a-2127-422b-91ae-364da2661108 | dev.icinga.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.