PT-2018-10686 · Centreon · Centreon+1
Publicado
2018-06-25
·
Atualizado
2022-05-14
·
CVE-2018-11587
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Centreon version 3.4.6
Centreon Web version 2.8.23
Description
The issue concerns Remote Code Execution via the RPN value in the Virtual Metric form. This is specifically related to the centreonGraph.class.php file.
Recommendations
For Centreon version 3.4.6, update to a version that fixes this issue.
For Centreon Web version 2.8.23, update to a version that fixes this issue.
As a temporary workaround, consider restricting access to the Virtual Metric form in centreonGraph.class.php to minimize the risk of exploitation.
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centreon
Centreon Web