Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nrpe | Aug 30, 2017 | Jul 9, 2013 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 9, 2013 |
| Debian | — | Upgrade nagios-nrpe | Jul 30, 2024 | Jul 9, 2013 |
| Gentoo Linux | — | Upgrade net-analyzer/nrpe. | Oct 30, 2017 | Jul 9, 2013 |
| Suse | — | Upgrade nagios-nrpe-debuginfoUpgrade nagios-plugins-nrpeUpgrade nagios-plugins-nrpe-debuginfoUpgrade nagios-nrpe-docUpgrade nagios-nrpeUpgrade nagios-nrpe-debugsource | Feb 17, 2015 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub