CVE-2023-28354 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plu…
Critical CVSS: 9.8

CVE-2023-28354

An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in default installations are configured to accept command control characters and pass them to command-line interpreters for NRPE plugin execution. This allows the attacker to escape NRPE plugin execution and execute commands remotely on the target as NT_AUTHORITY\SYSTEM.
Vendor
-
Product
-
CWE
CWE-94
Yayın Tarihi
2025-01-09 22:15:26
Güncelleme
2025-01-10 18:15:18
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar