šŸ“¦

centreon

Vendor: centreon

Actively Exploited 0 CISA KEV List
PoC / Exploits 7 Code Available
Total RCEs 12 Remote Access
Total CVEs 90 Total Indexed
Avg. EPSS 10.74% Exploit Prob.
Latest CVE CVE-2024-39843 Sep 23

Security Vulnerability Index

Page 4 / 9
6.1 CVSS

Open redirect via parameter ā€˜p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.

EPSS: 0.85%
9.8 CVSS

An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.

EPSS: 1.79%
7.5 CVSS

An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.

EPSS: 1.69%
7.5 CVSS

An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/service/refreshMacroAjax.php.

EPSS: 1.82%
8.8 CVSS

An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.

EPSS: 1.69%
7.5 CVSS

An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/host/refreshMacroAjax.php.

EPSS: 1.33%
7.5 CVSS

An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2. It provides sensitive information via an unauthenticated direct request for include/monitoring/recurrentDowntime/GetXMLHost4Services.php.

EPSS: 1.68%
8.8 CVSS

Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.

EPSS: 4.12%
7.8 CVSS

Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrapper_perl is a setuid executable allowing execution of Perl scripts with root privileges.)

EPSS: 0.36%
6.1 CVSS

Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.

EPSS: 1.27%