SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-7108

Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service…

MEDIUM 5.5EPSS 59.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 59.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.

CVSS 2.0
5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
EPSS
59.55% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
nagios/nagios · icinga/icinga
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.