vendor:
Centreon
by:
Omri Baso, Fabien Aunay
7.5
CVSS
HIGH
Remote Command Execution
RCE
CWE
Product Name: Centreon
Affected Version From: 19.10.2005
Affected Version To: 19.10.2005
Patch Exists: NO
Related CWE: -
CPE: a:centreon:centreon:19.10.5
Platforms Tested: CentOS 7.7
2020
Centreon 19.10.5 – ‘Pollers’ Remote Command Execution
User input isn't sanitized for safe use - and it is possible to gain a Remote Code Execution of the server hosting the Centreon Service leading to a full server takeover with the user "apache"
Mitigation:
Implement input sanitization and validation to prevent remote command execution vulnerabilities. Regularly update to the latest version of Centreon to ensure that security patches are applied.