Vulnerability record · CVE-2013-3502 · published 8 May 2013
CVE-2013-3502: GroundWork Monitor monarch_scan.cgi command execution via SSO cookie
Gwos · Groundwork Monitor
The monarch_scan.cgi script in the MONARCH component of GroundWork Monitor Enterprise 6.7.0 fails to properly validate authorization, allowing a remote authenticated user to execute arbitrary commands by leveraging a JOSSO SSO cookie. This is a role access control bypass that turns a low-privileged authenticated session into command execution on the monitoring server.
Description
monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and consequently obtain sensitive information, by leveraging a JOSSO SSO cookie.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityRemote authenticated command execution with public exploit references and very high EPSS, though it requires valid credentials and is not in KEV.
What it is
The monarch_scan.cgi script in the MONARCH component of GroundWork Monitor Enterprise 6.7.0 fails to properly validate authorization, allowing a remote authenticated user to execute arbitrary commands by leveraging a JOSSO SSO cookie. This is a role access control bypass that turns a low-privileged authenticated session into command execution on the monitoring server.
Impact
An attacker with a valid account gains arbitrary command execution on the GroundWork Monitor host and can read sensitive information, including credentials and monitoring data.
Attack surface
Reachable over the network through the web interface at monarch_scan.cgi; the attacker must be authenticated and supply a JOSSO SSO cookie, and no user interaction beyond that is described.
Exploitation
Not listed in CISA KEV, but EPSS is 0.537 (98.9th percentile) and public Exploit-DB and CERT/CC references exist, indicating exploit code and active interest.
What to do
- Apply the vendor fix referenced in GroundWork support advisory SA6.7.0-1 for the role access control bypass.
- Upgrade GroundWork Monitor Enterprise beyond 6.7.0 if a fixed release is available.
- Restrict network access to the GroundWork web interface and MONARCH CGI endpoints to trusted management networks.
- Audit and rotate JOSSO SSO cookies and credentials, and enforce least privilege on GroundWork accounts.
- Monitor and limit privileges of accounts that can reach monarch_scan.cgi.
Detection
- Review web server and GroundWork logs for requests to monarch_scan.cgi, especially with unusual parameters or from unexpected source IPs.
- Alert on command execution or child process creation spawned by the GroundWork web/CGI process.
- Monitor for anomalous outbound connections or file reads from the GroundWork host following monarch_scan.cgi access.
- Correlate JOSSO SSO cookie use with access to MONARCH endpoints outside normal administrative patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-3502 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-3502), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.