Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 21 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cat03
Cat03 lilac-reloaded |
|
| Vendors & Products |
Cat03
Cat03 lilac-reloaded |
Fri, 19 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a crafted POST request to the autodiscovery endpoint. | |
| Title | Lilac-Reloaded for Nagios 2.0.8 Remote Code Execution via Autodiscovery | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:08:05.835Z
Reserved: 2025-12-16T19:22:09.998Z
Link: CVE-2023-53948
Updated: 2025-12-19T21:50:20.192Z
Status : Deferred
Published: 2025-12-19T21:15:50.207
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-53948
No data.
OpenCVE Enrichment
Updated: 2025-12-21T21:12:43Z