Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-19699

Опубликовано: 06 апр. 2020
Источник: nvd
CVSS3: 7.2
CVSS2: 9
EPSS Низкий

Описание

There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To exploit the vulnerability, someone must have Admin access to the Centreon Web Interface and create a custom main.php?p=60803&type=3 command. The user must then set the Pollers Post-Restart Command to this previously created command via the main.php?p=60901&o=c&server_id=1 URI. This is triggered via an export of the Poller Configuration.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:centreon:centreon:*:*:*:*:*:*:*:*
Версия до 19.10 (включая)

EPSS

Процентиль: 92%
0.08905
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-269

Связанные уязвимости

github
больше 3 лет назад

There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To exploit the vulnerability, someone must have Admin access to the Centreon Web Interface and create a custom main.php?p=60803&type=3 command. The user must then set the Pollers Post-Restart Command to this previously created command via the main.php?p=60901&o=c&server_id=1 URI. This is triggered via an export of the Poller Configuration.

EPSS

Процентиль: 92%
0.08905
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-269