CVE-2014-2913
Summary
| CVE | CVE-2014-2913 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-07 10:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows newlines as "expected behavior." Also, this issue can only occur when the administrator enables the "dont_blame_nrpe" option in nrpe.conf despite the "HIGH security risk" warning within the comments |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 23 Update: nrpe-2.15-7.fc23 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Nagios Remote Plugin Executor 'nrpe.c' Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Full Disclosure: Re: NRPE - Nagios Remote Plugin Executor <= 2.15 Remote Command Execution | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| Full Disclosure: NRPE - Nagios Remote Plugin Executor <= 2.15 Remote Command Execution | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| oss-sec: Re: CVE Request: Nagios Remote Plugin Executor <= 2.15 Remote Command Execution | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| openSUSE-SU-2014:0603-1: moderate: update for nagios-nrpe | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2014:0594-1: moderate: update for nrpe | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] SUSE-SU-2014:0682-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| oss-sec: Re: CVE Request: Nagios Remote Plugin Executor <= 2.15 Remote Command Execution | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.