← Vulnerability feed

Vulnerability record · CVE-2013-3502 · published 8 May 2013

CVE-2013-3502: GroundWork Monitor monarch_scan.cgi command execution via SSO cookie

Gwos · Groundwork Monitor

The monarch_scan.cgi script in the MONARCH component of GroundWork Monitor Enterprise 6.7.0 fails to properly validate authorization, allowing a remote authenticated user to execute arbitrary commands by leveraging a JOSSO SSO cookie. This is a role access control bypass that turns a low-privileged authenticated session into command execution on the monitoring server.

6.5 CVSS 2.0 Medium EPSS 54% · top 1.0% CWE-255 · CWE-255
6.5CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and consequently obtain sensitive information, by leveraging a JOSSO SSO cookie.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote authenticated command execution with public exploit references and very high EPSS, though it requires valid credentials and is not in KEV.

What it is

The monarch_scan.cgi script in the MONARCH component of GroundWork Monitor Enterprise 6.7.0 fails to properly validate authorization, allowing a remote authenticated user to execute arbitrary commands by leveraging a JOSSO SSO cookie. This is a role access control bypass that turns a low-privileged authenticated session into command execution on the monitoring server.

Impact

An attacker with a valid account gains arbitrary command execution on the GroundWork Monitor host and can read sensitive information, including credentials and monitoring data.

Attack surface

Reachable over the network through the web interface at monarch_scan.cgi; the attacker must be authenticated and supply a JOSSO SSO cookie, and no user interaction beyond that is described.

Exploitation

Not listed in CISA KEV, but EPSS is 0.537 (98.9th percentile) and public Exploit-DB and CERT/CC references exist, indicating exploit code and active interest.

What to do

  • Apply the vendor fix referenced in GroundWork support advisory SA6.7.0-1 for the role access control bypass.
  • Upgrade GroundWork Monitor Enterprise beyond 6.7.0 if a fixed release is available.
  • Restrict network access to the GroundWork web interface and MONARCH CGI endpoints to trusted management networks.
  • Audit and rotate JOSSO SSO cookies and credentials, and enforce least privilege on GroundWork accounts.
  • Monitor and limit privileges of accounts that can reach monarch_scan.cgi.

Detection

  • Review web server and GroundWork logs for requests to monarch_scan.cgi, especially with unusual parameters or from unexpected source IPs.
  • Alert on command execution or child process creation spawned by the GroundWork web/CGI process.
  • Monitor for anomalous outbound connections or file reads from the GroundWork host following monarch_scan.cgi access.
  • Correlate JOSSO SSO cookie use with access to MONARCH endpoints outside normal administrative patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-3502 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2013-3499Gwos groundwork monitor permissions and access controls vulnerabilityGroundWork Monitor Enterprise 6.7.0 performs authentication on the basis of the HTTP Referer header, which allows remote attackers to obtain administ…EPSS 3.2%7.5CVE-2013-3500Gwos groundwork monitor permissions and access controls vulnerabilityThe Foundation webapp admin interface in GroundWork Monitor Enterprise 6.7.0 uses the nagios account as the owner of writable files under /usr/local/…EPSS 2.4%7.5CVE-2013-3506Gwos groundwork monitor permissions and access controls vulnerabilitycgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which a…EPSS 2.5%6.8CVE-2013-3513Gwos groundwork monitor cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in the Noma component in GroundWork Monitor Enterprise 6.7.0 allow remote attackers to hij…EPSS 0.72%6.5CVE-2013-3509Gwos groundwork monitor permissions and access controls vulnerabilityhtml/System-NeDi.php in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via…EPSS 1.9%6.5CVE-2013-3510Gwos groundwork monitor sql injection vulnerabilityMultiple SQL injection vulnerabilities in GroundWork Monitor Enterprise 6.7.0 allow remote authenticated users to execute arbitrary SQL commands via …EPSS 1.3%6.5CVE-2013-3512Gwos groundwork monitor improper input validation vulnerabilityThe Cacti component in GroundWork Monitor Enterprise 6.7.0 does not properly perform authorization checks, which allows remote authenticated users to…EPSS 1.5%6.5CVE-2013-3508Gwos groundwork monitor code injection vulnerabilityhtml/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated us…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2013-3502), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.