Lilac-Reloaded for Nagios 2.0.8 Remote Code Execution via Autodiscovery
Vulnerability Description
Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a crafted POST request to the autodiscovery endpoint.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53948
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- max / Zoltan Padanyi
Affected Vendor
cat03
View all reports →