CVE-2019-13024
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 32.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 32.16% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- centreon/centreon
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/153504/Centreon-19.04-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10/centreon-18.10.6.html
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04/centreon-19.04.3.html
- https://gist.github.com/mhaskar/c4255f6cf45b19b8a852c780f50576daExploit, Third Party Advisory
- https://github.com/centreon/centreon/pull/7694
- https://shells.systems/centreon-v19-04-remote-code-execution-cve-2019-13024/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/153504/Centreon-19.04-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10/centreon-18.10.6.html
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04/centreon-19.04.3.html
- https://gist.github.com/mhaskar/c4255f6cf45b19b8a852c780f50576daExploit, Third Party Advisory
- https://github.com/centreon/centreon/pull/7694
- https://shells.systems/centreon-v19-04-remote-code-execution-cve-2019-13024/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.