NRPE_Security

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
y-badrou
Posts: 3
Joined: Fri Aug 21, 2020 2:09 am

NRPE_Security

Post by y-badrou »

Hi,

Until now, I really want to know what are security vulnerabilities related to NRPE ? What do I have to do to prevent and avoid those vulnerabilities ?

Thank you
User avatar
jbrunkow
Posts: 441
Joined: Fri Mar 13, 2020 10:45 am

Re: NRPE_Security

Post by jbrunkow »

Hello @y-badrou!

Welcome to the forum. :D

This is a fairly broad topic, but I will do the best I can. The exact security procedures you follow should be defined by your information security team. The best policies may vary depending on how your environment is set up and what compliance regulation your industry is subject to.

There was one vulnerability reported for NRPE, but it is only present if the administrator enables dont_blame_nrpe in the nrpe.conf and has since been fixed.
CVE 2014-2913

Your first defense should be to put your systems behind a strong firewall. If you are not able to do that, make sure the connections between devices is encrypted. If you need this system to be super secure for some reason, you could even setup Nagios offline.

I hope that helps! Let me know if I can answer any more specific questions.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.

Be sure to check out our Knowledgebase for helpful articles and solutions!
y-badrou
Posts: 3
Joined: Fri Aug 21, 2020 2:09 am

Re: NRPE_Security

Post by y-badrou »

Thank you so much for your answer :D
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: NRPE_Security

Post by scottwilkerson »

y-badrou wrote:Thank you so much for your answer :D
No problem

Locking thread
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
Locked