← Vulnerability feed

Vulnerability record · CVE-2012-6096 · published 22 January 2013

CVE-2012-6096: Nagios Core and Icinga history.cgi stack buffer overflow

Nagios · Nagios

The get_history function in history.cgi in Nagios Core before 3.4.4 and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4 contains multiple stack-based buffer overflows. A long host_name (host parameter) or svc_description value can overwrite stack memory, and the flaw matters because history.cgi is a network-facing CGI that can be reached without authentication.

7.5 CVSS 2.0 High EPSS 66% · top 0.7% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
32References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote code execution with public exploits and very high EPSS, though not confirmed in KEV.

What it is

The get_history function in history.cgi in Nagios Core before 3.4.4 and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4 contains multiple stack-based buffer overflows. A long host_name (host parameter) or svc_description value can overwrite stack memory, and the flaw matters because history.cgi is a network-facing CGI that can be reached without authentication.

Impact

A remote attacker can execute arbitrary code with the privileges of the web server or CGI process, or at minimum crash the service. Successful exploitation gives code execution on the monitoring host, which often holds broad infrastructure access.

Attack surface

Reached over the network via HTTP requests to history.cgi with crafted host or service parameters, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required according to the CVSS vector and description.

Exploitation

Public exploit code exists in Exploit-DB (24084, 24159) and SecurityFocus, and EPSS is 0.6645 (99.2 percentile), indicating high likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild activity is recorded here.

What to do

  • Upgrade Nagios Core to 3.4.4 or later and Icinga to 1.6.2, 1.7.4, or 1.8.4 or later.
  • Apply the vendor and distribution patches referenced by Debian DSA-2616/DSA-2653 and openSUSE updates if immediate upgrade is not possible.
  • Restrict access to history.cgi and the Nagios/Icinga web interface to trusted management networks or authenticated reverse proxies.
  • Run the web/CGI process with least privilege and isolate the monitoring server from general user networks.

Detection

  • Inspect web and CGI logs for requests to history.cgi with unusually long host or service parameters.
  • Alert on crashes or restarts of the Nagios/Icinga CGI or web server processes.
  • Monitor for unexpected child processes or outbound connections originating from the monitoring web server.
  • Use network or WAF signatures for oversized parameters targeting history.cgi.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.grok.org.uk/pipermail/full-disclosure/2012-December/089125.html
http://lists.opensuse.org/opensuse-updates/2013-01/msg00033.html
http://lists.opensuse.org/opensuse-updates/2013-01/msg00060.html
http://lists.opensuse.org/opensuse-updates/2013-01/msg00077.html
http://lists.opensuse.org/opensuse-updates/2013-01/msg00088.html
http://secunia.com/advisories/51863 Vendor Advisory
http://www.debian.org/security/2013/dsa-2616
http://www.debian.org/security/2013/dsa-2653
http://www.exploit-db.com/exploits/24084 Exploit
http://www.exploit-db.com/exploits/24159 Exploit
http://www.nagios.org/projects/nagioscore/history/core-3x
http://www.osvdb.org/89170
http://www.securityfocus.com/bid/56879 Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=893269
https://dev.icinga.org/issues/3532 Vendor Advisory
https://www.icinga.org/2013/01/14/icinga-1-6-2-1-7-4-1-8-4-released/
http://lists.grok.org.uk/pipermail/full-disclosure/2012-December/089125.html
http://lists.opensuse.org/opensuse-updates/2013-01/msg00033.html
http://lists.opensuse.org/opensuse-updates/2013-01/msg00060.html
http://lists.opensuse.org/opensuse-updates/2013-01/msg00077.html
http://lists.opensuse.org/opensuse-updates/2013-01/msg00088.html
http://secunia.com/advisories/51863 Vendor Advisory
http://www.debian.org/security/2013/dsa-2616
http://www.debian.org/security/2013/dsa-2653
http://www.exploit-db.com/exploits/24084 Exploit
http://www.exploit-db.com/exploits/24159 Exploit
http://www.nagios.org/projects/nagioscore/history/core-3x
http://www.osvdb.org/89170
http://www.securityfocus.com/bid/56879 Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=893269
https://dev.icinga.org/issues/3532 Vendor Advisory
https://www.icinga.org/2013/01/14/icinga-1-6-2-1-7-4-1-8-4-released/

Track CVE-2012-6096 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4796Snoopy project snoopy os command injection vulnerabilityThe _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamat…EPSS 9.0%10.0CVE-2002-1959Nagios vulnerabilityNagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output.EPSS 3.9%9.8CVE-2024-49369Icinga improper certificate validation vulnerabilityIcinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor…EPSS 2.9%9.8CVE-2016-0726Nagios hard-coded credentials vulnerabilityThe Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote at…EPSS 2.3%9.8CVE-2008-7313Snoopy command injection vulnerabilityThe _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE…EPSS 4.5%9.8CVE-2014-5009Snoopy command injection vulnerabilitySnoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.EPSS 4.7%9.8CVE-2016-9565Nagios improper access control vulnerabilityMagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofin…EPSS 23%9.3CVE-2025-48057Icinga vulnerabilityIcinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for rep…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2012-6096), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.