📦 Centreon

by Centreon

🔍 What is Centreon?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-37558

CRITICAL CVSS 9.8 Aug 3, 2021

This is a critical SQL injection vulnerability in Centreon's MediaWiki integration that allows remote unauthenticated attackers to execute arbitrary SQL commands. It affects Centreon monitoring system...

CVE-2019-17647

CRITICAL CVSS 9.8 Mar 5, 2020

This SQL injection vulnerability in Centreon monitoring software allows attackers to execute arbitrary SQL commands via the instance parameter in hostXML.php. Affected systems include Centreon version...

CVE-2018-21024

CRITICAL CVSS 9.8 Oct 8, 2019

CVE-2018-21024 is an unrestricted file upload vulnerability in Centreon Web's licenseUpload.php that allows attackers to upload arbitrary files via POST requests. This affects Centreon Web installatio...

CVE-2019-16194

CRITICAL CVSS 9.8 Sep 25, 2019

This CVE describes a SQL injection vulnerability in Centreon monitoring software that allows attackers to execute arbitrary SQL commands via the svc_id parameter. Attackers can potentially access, mod...

CVE-2024-39842

HIGH CVSS 7.2 Sep 23, 2024

A SQL injection vulnerability in Centreon 24.04.2 allows authenticated high-privileged attackers to execute arbitrary SQL commands through user massive changes inputs. This could lead to data theft, m...

CVE-2022-42425

HIGH CVSS 8.8 Mar 29, 2023

CVE-2022-42425 is an SQL injection vulnerability in Centreon's poller broker configuration that allows authenticated attackers to escalate privileges to administrator level. This affects Centreon inst...

CVE-2022-42427

HIGH CVSS 8.8 Mar 29, 2023

This is an SQL injection vulnerability in Centreon's contact groups configuration page that allows authenticated attackers to escalate privileges to administrator level. It affects Centreon installati...

CVE-2022-42429

HIGH CVSS 8.8 Mar 29, 2023

CVE-2022-42429 is an SQL injection vulnerability in Centreon's poller broker configuration that allows authenticated attackers to escalate privileges to administrator level. This affects Centreon inst...

CVE-2021-37557

HIGH CVSS 8.8 Aug 3, 2021

A SQL injection vulnerability in Centreon's image generation component allows remote authenticated attackers with low privileges to execute arbitrary SQL commands. This affects Centreon monitoring sys...

CVE-2021-28053

HIGH CVSS 8.8 Jul 16, 2021

This SQL injection vulnerability in Centreon-Web allows authenticated attackers to execute arbitrary SQL commands through the Additional Information parameters in the user configuration interface. It ...

CVE-2019-19699

HIGH CVSS 7.2 Apr 6, 2020

This vulnerability allows authenticated attackers with admin access to Centreon's web interface to achieve remote code execution by misconfiguring poller commands. The exploit involves creating a mali...

CVE-2019-19487

HIGH CVSS 8.8 Mar 20, 2020

This vulnerability allows remote attackers to execute arbitrary commands on Centreon monitoring servers via command injection in the minPlayCommand.php file. Attackers can achieve remote code executio...

CVE-2019-17646

HIGH CVSS 7.5 Mar 5, 2020

This vulnerability in Centreon monitoring software allows unauthenticated attackers to access sensitive information via a direct API request. It affects Centreon versions before 18.10.8, 19.04.5, and ...

CVE-2019-17645

HIGH CVSS 7.5 Mar 5, 2020

This vulnerability in Centreon monitoring software allows unauthenticated attackers to access sensitive configuration information via a direct request to a specific PHP file. Affected organizations ar...

CVE-2019-17643

HIGH CVSS 7.5 Mar 4, 2020

This vulnerability in Centreon monitoring software allows unauthenticated attackers to access sensitive information via a direct request to a specific PHP file. It affects Centreon versions before the...

CVE-2020-9463

HIGH CVSS 8.8 Feb 28, 2020

This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands on Centreon monitoring servers by injecting shell metacharacters in the server_ip field of API r...

CVE-2019-20327

HIGH CVSS 7.8 Jan 16, 2020

CVE-2019-20327 is a privilege escalation vulnerability in Centreon monitoring software where the cwrapper_perl setuid executable has insecure permissions, allowing local attackers to execute arbitrary...