CVE-2009-2288 describes a critical command injection vulnerability in Nagios versions prior to 3.1.1, specifically within the statuswml.cgi script. This flaw allows unauthenticated remote attackers to execute arbitrary operating system commands by injecting shell metacharacters into the ping or Traceroute parameters. With a CVSS score of 7.5 (High) and an EPSS score of 0.933, this vulnerability is easily exploitable over the network with low attack complexity, leading to potential compromise of confidentiality, integrity, and availability. Exploit code is publicly available, including multiple Metasploit modules and entries in ExploitDB, indicating a high likelihood of exploitation. Despite its age, the high EPSS score suggests a significant threat, though there is no evidence of active exploitation in the wild or community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1.0CPE matchmatch criteria | cpe:2.3:a:nagios:nagios:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:nagios:nagios:1.0:*:*:*:*:*:*:* | ||
1.0b1CPE matchmatch criteria | cpe:2.3:a:nagios:nagios:1.0b1:*:*:*:*:*:*:* | ||
1.0b2CPE matchmatch criteria | cpe:2.3:a:nagios:nagios:1.0b2:*:*:*:*:*:*:* | ||
1.0b4CPE matchmatch criteria | cpe:2.3:a:nagios:nagios:1.0b4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.