This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Nagios First view 2013-07-09
Product Remote Plug In Executor Last view 2020-03-16
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:nagios:remote_plug_in_executor:3.2.1:*:*:*:*:*:*:* 2
cpe:2.3:a:nagios:remote_plug_in_executor:2.7.1:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:1.4:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:1.5:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.0b4:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:1.9:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.0b5:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.6:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.7:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.11:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.12:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:1.6:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:1.7:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.0:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.3:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.8.1:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.8b1:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:1.3:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.0b2:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.0b3:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.5.1:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.5.2:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.9:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.10:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:1.8:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.0b1:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.4:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.5:*:*:*:*:*:*:* 1
cpe:2.3:a:nagios:remote_plug_in_executor:2.8:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
7.5 2020-03-16 CVE-2020-6582

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

7.3 2020-03-16 CVE-2020-6581

Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection.

7.5 2013-07-09 CVE-2013-1362

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

CWE : Common Weakness Enumeration

%idName
33% (1) CWE-787 Out-of-bounds Write
33% (1) CWE-681 Incorrect Conversion between Numeric Types
33% (1) CWE-20 Improper Input Validation

Oval Markup Language : Definitions

OvalID Name
oval:org.mitre.oval:def:25913 SUSE-SU-2013:1219-1 -- Security update for nagios-nrpe, nagios-plugins-nrpe

SAINT Exploits

Description Link
Nagios Remote Plugin Executor Metacharacter Filtering Omission More info here

Snort® IPS/IDS

Date Description
2014-01-10 Nagios NRPE command execution attempt
RuleID : 26491 - Type : SERVER-OTHER - Revision : 6

Nessus® Vulnerability Scanner

id Description
2014-08-30 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201408-18.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2013-301.nasl - Type: ACT_GATHER_INFO
2013-09-04 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2013-203.nasl - Type: ACT_GATHER_INFO
2013-07-19 Name: The remote SuSE 11 host is missing one or more security updates.
File: suse_11_nagios-nrpe-130710.nasl - Type: ACT_GATHER_INFO
2013-07-12 Name: The remote Fedora host is missing a security update.
File: fedora_2013-9829.nasl - Type: ACT_GATHER_INFO
2013-07-12 Name: The remote Fedora host is missing a security update.
File: fedora_2013-9836.nasl - Type: ACT_GATHER_INFO
2013-07-12 Name: The remote Fedora host is missing a security update.
File: fedora_2013-9848.nasl - Type: ACT_GATHER_INFO
2013-05-09 Name: The monitoring service running on the remote host is affected by an arbitrary...
File: nagios_nrpe_2_14.nasl - Type: ACT_GATHER_INFO