Monit
Vendor:
First CVE: Nov 24, 2003 · Active for 22 years
7
Total CVEs
More Total CVEs than 85% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Monit over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 24, 2003
22 years ago
Most Recent CVE
Jul 18, 2023
1,105 days ago
CVE Severity & Scoring
Monit7 CVEs
29%
57%
14%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (42.9%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (42.9%)
High0 (0.0%)
Unknown4 (57.1%)
User Interaction
None3 (42.9%)
Unknown4 (57.1%)
Required0 (0.0%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None1 (14.3%)
Unknown4 (57.1%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1083HIGH Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request. | Dec 31, 2003 | 10.0 | 53 | NO | YES |
CVE-2004-1898HIGH Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username. | Dec 31, 2004 | 10.0 | 43 | NO | YES |
CVE-2019-11393CRITICAL An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password chang | Apr 22, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11455HIGH A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation | Apr 22, 2019 | 8.1 | 28 | NO | NO |
CVE-2022-26563HIGH An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization. | Jul 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2003-1084MEDIUM Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field. | Nov 24, 2003 | 5.0 | 20 | NO | NO |
CVE-2004-1899MEDIUM The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes. | Dec 31, 2004 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
28.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Monit
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.3_beta_2 | 2 | 7.5 | 9.1% | 0 | 1 |
| 4.2 | 2 | 7.5 | 9.1% | 0 | 1 |
| 4.1.1 | 2 | 7.5 | 9.1% | 0 | 1 |
| 4.1 | 4 | 7.5 | 10.8% | 0 | 2 |
| 4.0 | 4 | 7.5 | 10.8% | 0 | 2 |
| 3.2 | 4 | 7.5 | 10.8% | 0 | 2 |
| 3.1 | 4 | 7.5 | 10.8% | 0 | 2 |
| 3.0 | 4 | 7.5 | 10.8% | 0 | 2 |
| 2.4.3 | 2 | 7.5 | 12.4% | 0 | 1 |
| 2.4.2 | 2 | 7.5 | 12.4% | 0 | 1 |
| 2.4.1 | 2 | 7.5 | 12.4% | 0 | 1 |
| 2.4 | 2 | 7.5 | 12.4% | 0 | 1 |
| 2.3 | 2 | 7.5 | 12.4% | 0 | 1 |
| 2.2.1 | 2 | 7.5 | 12.4% | 0 | 1 |
| 2.2 | 2 | 7.5 | 12.4% | 0 | 1 |
| 2.1.1 | 2 | 7.5 | 12.4% | 0 | 1 |
| 2.1 | 2 | 7.5 | 12.4% | 0 | 1 |
| 2.0 | 2 | 7.5 | 12.4% | 0 | 1 |
| 1.4.1 | 2 | 7.5 | 12.4% | 0 | 1 |
| 1.4 | 4 | 7.5 | 10.8% | 0 | 2 |