vendor:
Centreon
by:
Fabien AUNAY, Omri Baso
7.5
CVSS
HIGH
Remote Command Execution
N/A
CWE
Product Name: Centreon
Affected Version From: 19.10.5
Affected Version To: 19.10.5
Patch Exists: NO
Related CWE: N/A
CPE: a:centreon:centreon:19.10.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS 7
2020
Centreon 19.10.5 – ‘centreontrapd’ Remote Command Execution
It is possible to get a reverse shell with a snmp trap and gain a pivot inside distributed architecture. Steps: Objective 1 : Create a SNMP trap or use linkDown OID with special command in action 3 Objective 2 : Create passive service and use App-Monitoring-Centreon-Service-Dummy Objective 3 : Assign service trap relation Objective 4 : Get centreon id reverse shell
Mitigation:
Create a SNMP trap or use linkDown OID with special command in action 3, Create passive service and use App-Monitoring-Centreon-Service-Dummy, Assign service trap relation, Get centreon id reverse shell