CVE-2013-1362: Nagios Remote Plug In Executor
High severity, CVSS 7.5. EPSS: 65.7% chance of exploitation in the next 30 days.
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
Affected products
- Nagios Remote Plug In Executor: up to and including 2.13; version 1.3 only; version 1.4 only; version 1.5 only; version 1.6 only; version 1.7 only; …
- Opensuse Opensuse: version 11.4 only; version 12.1 only; version 12.2 only
Published 2013-07-09. Last modified 2026-06-16.