VulnerabilityModified
CVE-2009-4368
Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) traceroute tool, and (3) ldap import, possibly related to improper authentication.
HIGH 10.0EPSS 2.54%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) traceroute tool, and (3) ldap import, possibly related to improper authentication.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.54% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- merethis/centreon
- Source
- cve@mitre.org
References
- http://osvdb.org/61183
- http://secunia.com/advisories/37808Vendor Advisory
- http://www.centreon.com/Development/changelog-2x.html
- http://www.securityfocus.com/bid/37383
- http://www.vupen.com/english/advisories/2009/3578Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54893
- http://osvdb.org/61183
- http://secunia.com/advisories/37808Vendor Advisory
- http://www.centreon.com/Development/changelog-2x.html
- http://www.securityfocus.com/bid/37383
- http://www.vupen.com/english/advisories/2009/3578Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54893
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.