Hi,
Until now, I really want to know what are security vulnerabilities related to NRPE ? What do I have to do to prevent and avoid those vulnerabilities ?
Thank you
NRPE_Security
Re: NRPE_Security
Hello @y-badrou!
Welcome to the forum.
This is a fairly broad topic, but I will do the best I can. The exact security procedures you follow should be defined by your information security team. The best policies may vary depending on how your environment is set up and what compliance regulation your industry is subject to.
There was one vulnerability reported for NRPE, but it is only present if the administrator enables dont_blame_nrpe in the nrpe.conf and has since been fixed.
CVE 2014-2913
Your first defense should be to put your systems behind a strong firewall. If you are not able to do that, make sure the connections between devices is encrypted. If you need this system to be super secure for some reason, you could even setup Nagios offline.
I hope that helps! Let me know if I can answer any more specific questions.
Welcome to the forum.
This is a fairly broad topic, but I will do the best I can. The exact security procedures you follow should be defined by your information security team. The best policies may vary depending on how your environment is set up and what compliance regulation your industry is subject to.
There was one vulnerability reported for NRPE, but it is only present if the administrator enables dont_blame_nrpe in the nrpe.conf and has since been fixed.
CVE 2014-2913
Your first defense should be to put your systems behind a strong firewall. If you are not able to do that, make sure the connections between devices is encrypted. If you need this system to be super secure for some reason, you could even setup Nagios offline.
I hope that helps! Let me know if I can answer any more specific questions.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.
Be sure to check out our Knowledgebase for helpful articles and solutions!
Be sure to check out our Knowledgebase for helpful articles and solutions!
Re: NRPE_Security
Thank you so much for your answer 
-
scottwilkerson
- DevOps Engineer
- Posts: 19396
- Joined: Tue Nov 15, 2011 3:11 pm
- Location: Nagios Enterprises
- Contact:
Re: NRPE_Security
No problemy-badrou wrote:Thank you so much for your answer
Locking thread