Vulnerability record · CVE-2013-3632 · published 29 September 2014
CVE-2013-3632: OpenMediaVault rpc.php cron service allows arbitrary command execution
Openmediavault · Openmediavault
The Cron service in rpc.php in OpenMediaVault fails to properly restrict the username parameter, letting a remote authenticated user schedule cron jobs as arbitrary users and run arbitrary commands. Because the flaw grants command execution with the privileges of any chosen account, it undermines the separation between low-privileged users and the system.
Description
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote authenticated command execution with high confidentiality, integrity and availability impact, plus public exploit code and very high EPSS, though it requires valid credentials and is not in KEV.
What it is
The Cron service in rpc.php in OpenMediaVault fails to properly restrict the username parameter, letting a remote authenticated user schedule cron jobs as arbitrary users and run arbitrary commands. Because the flaw grants command execution with the privileges of any chosen account, it undermines the separation between low-privileged users and the system.
Impact
An attacker with a valid account gains arbitrary command execution as other users, including potentially root, leading to full compromise of the OpenMediaVault host and its managed storage.
Attack surface
Reached over the network through rpc.php; the CVSS vector (AV:N/PR:L/UI:N) indicates a valid low-privileged account is required and no user interaction is needed.
Exploitation
Public exploit code exists (Exploit-DB 29323 and Metasploit-related references), and EPSS is 0.571 (99th percentile), though the CVE is not listed in CISA KEV.
What to do
- Apply the OpenMediaVault update that fixes the rpc.php cron handling; if no patch is available for your release, upgrade to a supported version.
- Restrict network access to rpc.php and the OpenMediaVault web interface to trusted management networks.
- Audit and minimize accounts with access to the OpenMediaVault interface, and remove unused accounts.
- Review cron jobs and system users for unauthorized entries created via the cron service.
Detection
- Monitor rpc.php requests for cron-related actions with unexpected or privileged username values.
- Alert on new or modified cron entries, especially those running as root or other privileged users.
- Correlate OpenMediaVault authentication logs with subsequent cron job creation and command execution events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-3632 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-3632), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.