Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-1892

57
FAUCET Score

CVE-2013-1892 is a critical vulnerability affecting MongoDB versions before 2.0.9 and 2.2.x before 2.2.4, as well as associated Red Hat products. This flaw allows remote authenticated users to trigger a denial of service or execute arbitrary code by sending a specially crafted request to the nativeHelper function. With a CVSS score of 6.0 and a FAUCET Risk Score of 98/100, this vulnerability presents a significant risk due to its network-based attack vector, medium attack complexity, and potential for partial confidentiality, integrity, and availability impacts. Exploit code is publicly available through Metasploit modules and ExploitDB, indicating a high likelihood of exploitation, although it is not currently listed on CISA's KEV catalog. The vulnerability has garnered notable community discussion and media coverage, further highlighting its importance.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.0.8CPE matchmatch criteria
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
1.2.0CPE matchmatch criteria
cpe:2.3:a:mongodb:mongodb:1.2.0:*:*:*:*:*:*:*
1.4.0CPE matchmatch criteria
cpe:2.3:a:mongodb:mongodb:1.4.0:*:*:*:*:*:*:*
1.6.0CPE matchmatch criteria
cpe:2.3:a:mongodb:mongodb:1.6.0:*:*:*:*:*:*:*
1.8.0CPE matchmatch criteria
cpe:2.3:a:mongodb:mongodb:1.8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.0MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
SINGLE
Exploitability Score
6.8
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
44.54%
Probability of exploitation in next 30 days
EPSS Percentile
98.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Metasploit: MongoDB nativeHelper.apply Remote Code Execution · Mar 24, 2013
ExploitDB: EDB-24947 · Apr 8, 2013
This CVE's current EPSS score of 0.4454 is in the 100th percentile among its peer group of 1,424 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: mongodb-0:1.6.4-6.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: pymongo-0:1.9-11.el6
View patch
redhatend of lifevia redhat_api
Product: OpenShift Enterprise 1Fixed in: mongodb

Vendor Advisories (1)

redhatCVE-2013-1892Important

MongoDB: Server Side JavaScript Includes allow Remote Code Execution

Mar 24, 2013

References

blog.scrt.ch / 2013/03/24/mongodb-0-day-ssji-to-rce
Exploit
lists.fedoraproject.org / pipermail/package-announce/2013-April/101630.html
lists.fedoraproject.org / pipermail/package-announce/2013-April/101679.html
rhn.redhat.com / errata/RHSA-2013-1170.html
Vendor Advisory
jira.mongodb.org / browse/SERVER-9124
exploit-db.com / exploits/24935
exploit-db.com / exploits/24947
mongodb.org / about/alerts
Vendor Advisory
openwall.com / lists/oss-security/2013/03/25/9