peter bassill · operator
$ cve CVE-2014-2913 JSON

CVE-2014-2913 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 15.3% (pctl 97)

Patch early

A public exploit exists.

Description

Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows newlines as "expected behavior." Also, this issue can only occur when the administrator enables the "dont_blame_nrpe" option in nrpe.conf despite the "HIGH security risk" warning within the comments

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS15.31% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2014-05-07
Last modified2026-06-17

Affected (2)

VendorProduct
nagiosremote plugin executor
opensuseopensuse

Public exploits

SourceTitleDate
exploit-dbNRPE 2.15 - Remote Code Execution2014-08-29
exploit-dbNRPE 2.15 - Remote Command Execution2014-04-18

References

→ the Explorer  ·  watch your stack  ·  NVD