CVE-2023-37154: Nagios Plugins

High severity, CVSS 8.4. EPSS: 0.5% chance of exploitation in the next 30 days.

check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.

Affected products

  • Nagios Plugins: before 2.4.5 (fixed in 2.4.5)

Published 2024-10-09. Last modified 2026-06-17.