CVE-2023-37154: Nagios Plugins
High severity, CVSS 8.4. EPSS: 0.5% chance of exploitation in the next 30 days.
check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.
Affected products
- Nagios Plugins: before 2.4.5 (fixed in 2.4.5)
Published 2024-10-09. Last modified 2026-06-17.